ACCEPT tcp -- anywhere anywhere tcp dpt:ssh limit: up to 1/min burst 2 mode srcip
(Oh, and PasswordAuthentication is off too.)
-A PORTS -p tcp -m tcp --dport 22 -m hashlimit --hashlimit-upto 1/min --hashlimit-burst 2 --hashlimit-mode srcip --hashlimit-name ip4-ssh-brute -j ACCEPT
(Oh, and PasswordAuthentication is off too.)