
Every ban in a firewall is a rule, and every rule is checked for every packet. A list of ten thousand addresses turns into ten thousand rules in order. ipset stores the addresses in a hash table instead, so one iptables rule checks the set in a single lookup, whatever its size.
Install ipset
Keep the list in a text file
One address or CIDR range per line. Comments start with #. Keep the file under version control, so every change has a reason.
Load the set with a script
The script creates the set if needed, rebuilds it from the file, and adds the single iptables rule that drops anything in the set. It reads the last line even when the file has no trailing newline.
Test it
Run the script, then check one address from the list and one outside it. ipset test exits 0 when the address is in the set.
Keep it across reboots
ipset sets live in memory, so a reboot empties them. Save the set once it's right, restore it at boot, and run the load script after that if the file has changed.
Keep the list short
A range can cover more people than the abuse you're blocking. Review every /24 before you add it, check your own logs for the addresses you care about, and remove entries that stop showing up. Keep the rules that protect SSH and the public site in the firewall script, not in this list.
Checking your own response headers by hand gets old fast. osec Scan grades them in seconds, free.

Sources
• ipset project documentation: https://ipset.netfilter.org/
• iptables set match (netfilter): https://ipset.netfilter.org/iptables-extensions.man.html