Currently, the networking set is very messy. It is better to contain them into another attribute set and categorizing them by the interfaces that is supposed to contain them. I should've done this some time ago.
Among other things, Plover now ignores certain IP for fail2ban. This is for the VPN users that are placed in that range.