Add support for matching on port ranges to the conntrack match. iptables patch will follow soon.