Perfect, if you know it, set it statically into the config file.
We never know how cloud providers manage their FW rules :/
May be you can still access to your PVE host by SSH because of a static rule (eg. a non-blocking rule) from their side, or their contrack is still alive, I dont know...