{ ... }: { networking.firewall = { enable = true; allowedTCPPorts = [ ]; allowedUDPPorts = [ ]; }; }