Genuinely curious, how would you block an attacker from getting to your SSH port without knowing the path you will connect from (which is the case for remote access) at configuration time?
I don‘t see how Path-Aware Networking would replace a VPN solution