Docs I Wish I Had

Debian and iptables when firewalld or ufw aren't around

To drop all internet traffic that is new iptables -A INPUT -i eth0 -s 0.0.0.0/0 -m conntrack --ctstate NEW -j DROP

To allow only your ip on tcp/22 iptables -A INPUT -i eth0 -s a.b.c.d/32 -m conntrack --ctstate NEW -j ACCEPT