you can create an ipset "blacklist" at datacenter level.
The name "blacklist" is specific. They are a default hidden rule droping all traffic coming from this ipset.
If you want to use a custom ipset, the only way is to create a security group, with a rule blocking the ipset, and add this security group in every vm firewall.