When enabling masquerading, we need to allow the traffic to go through
so we need the FORWARD rules as well, for source and destination
networks.
Also support multiple destinations or sources for ipv4/ipv6 suffixed
rules with a REGEX.
Change-Id: I48aa95b96c762a72273b5b0b714a04da7ee69a40