I've had decent luck using APF's global trust files for syncing up allow lists across hosts. It isn't well-documented, and there's a lot of bells and whistles and hoopla with APF that may annoy people who prefer raw iptables, but it works.
Your configuration management/deployment system should probably be able to handle that kind of thing, too. Since it will know about new servers before anything else does, that might be the most effective way to go...
Also: the private network is, from a security standpoint, a public network. Don't try to save iptables space that way

_________________
Code:
/* TODO: need to add signature to posts */