System Admin >Intrusion Detection

In the current freepbx distro iptables is launched by a script so we cannot webmin to edit rules. do we just do a -a for a new rule and then an “iptable save” to make it persistent across reboots? I want to block all SSH but a small group of known IPs for example. or allow sip and rtp only from another group of IPs.
Thanks