There are 2 extra chains - to log a connection and accept it, and to log a connection and drop it. I’ve only used log and accept for testing.
The default action on input chain is also changed to drop.
SSH port gets connection attempts counted - 20 connections within 10 minutes from the same IP and it goes to log and drop. I could just drop it, but for now I feel immense satisfaction knowing that some bot is waiting for timeout instead of attempting the next username/pass.
I’ve tried a similar thing with https because lemmy.world was dosing me. It did work, but I’ve now commented it out since Lemmy software has become more robust. Lemmy.world still sucks from my, as an instance owner, perspective, but it no longer bombards me periodically.