^(?!sub1|sub2).*(\.example\.com)
It's a small /30 block routed via my primary WAN IP.How are these IPs provided to you? e.g. Does the ISP expect the IPs all to be available on your WAN interface or is the ISP routing a block of public IPs via an independent link network (using a different IP range).
add action=dst-nat chain=dstnat disabled=no dst-address-type=local dst-port=1701 in-interface=ether1 protocol=udp to-addresses=192.168.1.1 to-ports=1701