Access control / firewalls / iptables

What’s the best way to manage IP based access control to stacks on Rancher hosts? Rules in the INPUT chain seem to be bypassed (and even if they worked would need to be manually added to each host)

I’ve worked around this limitation by moving my IP access control to an external firewall.