{ config, ... }:
{
  networking.firewall = {
    allowedUDPPorts = [ 51820 ];
  };

  networking.wireguard.interfaces = {
    "${config.ips.wgInt}" = {
      # Define IP of client in per device config
      listenPort = 51820;
      privateKey = config.secrets.wgClientPriv;
      peers = [
        { # 0.0.0.0 makes wg act like a traditional VPN
          publicKey = config.secrets.wgServerPub;
          allowedIPs = [ "0.0.0.0/0" ];
          endpoint = "sv.${config.secrets.jimDomain}:51820";
          persistentKeepalive = 25;
        }
      ];
    };
  };
}