At the present time, from the section [Router]->[Virtual Server] you can create single TCP/UDP port forwarding.
In any case, if you know the syntax of the iptables comand you could forward a range of port.
I think the better place in which you should create the DNAT is the PREROUTING chain because it is not manipulated by the Firewall GUI of Zeroshell.
In the near future, I will enable the port range forwarding from the web gui interface too.
Yes, I will allow to change the MAC address of the network interfaces by using the web admin interface. If you want to do it now, you just have to run the following commands by using the VGA or serial console: