I use CSF.
You need to allow UDP as well if your assets use UDP.
If your SSH port is still 22. I would change that as well.
Also if your using DigitalOcean / Hetzner you can use their firewall for extra protection.
In CSF you have a deny list. I denied all TOR IP’s