understanding fail2ban with iptables: https://www.the-art-of-web.com/system/fail2ban/ https://www.digitalocean.com/community/tutorials/how-fail2ban-works-to-protect-services-on-a-linux-server
- autorize new port in google firewall (common to all instances in the same zone):
with gloud command line:
gcloud compute firewall-rules create ssh-alternative-2224 --allow tcp:2224