Multiple Address specification or match

> iptables/netfilter has to be efficient, rules generation script has to
> be elegant. Having 3 rules is as efficient as your masked "or" rules if
> it was coded and 3 separate rules are more simple than your global one
> so in a way this is more elegant.

For hipac this is true, but not really when using iptables.


