CrowdSec scans also firewall logs like PSAD and much more applicative logs types than fail2ban. That being said I use tailscale to ssh to my servers.
Is it necessary to add a vpn connexion to a server on top of the ssh one? Here is someone else asking the same question: https://news.ycombinator.com/item?id=35957349
I would be interested to have your feedback.