But is there any real requirement of it, as src port are mostly random and have no practical meaning. Besides, will not it be better if we have a provision to create an ipset with maximum say 4 elements and those elements can be from ANY allowed elements i.e. ip, net, iface, port, mark, mac, etc.