-networking.firewall.allowedTCPPorts = [ 22 ]; +networking.firewall.interfaces."tailscale0".allowedTCPPorts = [ 22 ];