You certainly wont regret having a emergency ipset of 3.5M entries:
[8690887.043966] SLUB: Unable to allocate memory on node -1 (gfp=0x8020)
[8690887.043969] cache: kmalloc-64, object size: 64, buffer size: 64, default order: 0, min order: 0
[8690887.043974] node 0: slabs: 32738, objs: 2095232, free: 0
[8691714.855952] ipset: page allocation failure: order:0, mode:0x200020
[8691714.855965] CPU: 0 PID: 11215 Comm: ipset Not tainted 3.10.0-1160.119.1.el7.x86_64 #1
[8691714.855967] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011I'm sure that every packet that needs to this ipset is like when something drives into a concrete wall