line 1 of First Set will allow INBOUND port 22 traffic if connection = NEW CONNECTION.Line 2 of First set seems to be not necessary due to only allows port 22 traffic for a set network range also must be a new connections. Howver the previous rule on line 2 has already allowed the traffic through.
This seem wrong or incomplete
2nd set line 1, Allow INBOUND traffic on the0 if port = 22 and is new or established connectionsLine 2, Alllow OUTBOUND traffic if device = eth0 & port = 22 & connection is established
This will allow SSH connections to this host and will also allow outgoing SSH.
2 nd set is your better option