-A INPUT -p tcp --dport 22 -m set --match-set anynodes src -j ACCEPT
-A OUTPUT -p tcp --sport 22 -m set --match-set anynodes dst -j ACCEPT
create anynodes hash:net family inet hashsize 1024 maxelem 65536
add anynodes 10.7.1.0/24
add anynodes 10.7.3.0/24
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]