I'm sure that's initially due to a limitation of IPTABLES itself. You can provide a contiguous range or a single service, however, most service groups comprise of multiple, discontiguous services.
The Astaro team could do such an implementation, however logic would need to be developed to translate one "rule" into multiple IPTABLES chains. It's already been done for multiple networks or hosts - just needs to be applied to services as well.
[ 08 February 2002: Message edited by: HTMLSpinnr ]