We're running fail2ban jails to protect server2 & server3 from baddies. It can probably serve as a substitute for the mishmash of iptables, httpd user-agent level, httpd ip label, hosts.deny level protection we have had on sourceware. It operates via firewalld, cooperating with the normal zones/services level of protection already there.
The sshd jail is configured to temporarily block ip addresses that repeatedly make failing ssh authentication connections.
There is a family of preconfigured jails we can use, and we can also create our own for random administrative blocking purposes (bad web spiders etc). fail2ban can make bans temporary or permanent. Will probably set up a few jails for a range of these.