Você pode tentar usar ipsets
If you want to
- store multiple IP addresses or port numbers and match against the collection by iptables at one swoop;
- dynamically update iptables rules against IP addresses or ports without performance penalty;
- express complex IP address and ports based rulesets with one single iptables rule and benefit from the speed of IP sets
then ipset may be the proper tool for you.
Vale a pena notar que:
IP sets are a framework inside the Linux kernel, which can be administered by the ipset utility
E sim, parece que o site não foi atualizado desde 1996. Por alguma razão, as fontes de notícias de segurança de computadores e as páginas de projetos de software / firmware de baixo nível parecem muito com isso.