sudo firewall-cmd --add-rich-rule="rule family='ipv4' source address='89.20.160.77' reject" --timeout=1h

Valid values for timeout - numbers followed by s, m or h

Documentation