I mapped the SSH port to 122 on the external network while it stays 22 on the LAN. Then, I limit the number of connectons to port 122 at the firewall, using iptables (https://www.cyberciti.biz/tips/howto-limit-linux-syn-attacks...).
Now the failed logins on ssh is down to 1-2 per day instead of hundreds.