How to block / blacklist IP-address

It’s kind of “expected” for any server exposed to the internet to be targeted by bots roaming and brute-forcing servers, and fail2ban already handle this using its autoban mechanism (and c.f. the recidive jail for recidivers who get banned for much longer) …

I doubt there are some magic solutions … you can be much more agressive like “ban all IP blocks from china and other countries that are know to be sources of attacks” but ultimately you may get unexpected side effect (e.g. legit visitors unable to access your server, or banning yourself forever, or …) and the security gain is low.

Alternatively you can change the SSH port (not forgetting to also propagate it on fail2ban’s conf)

But to know exactly what’s the right way to proceed, you elaborate what’s your concern exactly.