Hi,
Applying the filter on the vlan interface without specifying the destination would also block transit ssh traffic.
Best is to apply the filter on loopback logical interfaces.
If you dont mind sharing the config and a traceroute to the vlan interface IP from the host, we could take a look at this behavior.
Cheers,
Ashvin