This makes more sense than blocking inbound traffic for specific IP
addresses where SSH doesn't make sense.
This orders sshd.service after network-online.target since otherwise
ListenAddress can fail to work with specific IP addresses assigned by
systemd-networkd.