This page has some relevant information but I don't want to mess up my production firewall messing with it. How would I do this with ipset and bastille firewall in ispconfig? https://mattwilcox.net/web-development/unexpected-ddos-blocking-china-with-ipset-and-iptables
I think you awnser is already written on that webpage. ISPconfig use a old firewall what is better to disable and use the normal IPTables and then you also can follow that page with instructions