Can't mess with IP tables on the server. Well I could but that would require a week of paperwork ;)
Something like match ip src
10.208.208.0/21 match ip should work in tc but how do I say not port? I know I can say sport but not sure about port and I have no idea how to say "not port"
as for latency range delay takes 2 arguments so it would be netem delay 100ms 150ms would be from 100ms-250ms delay. IIRC
Also you are using outbound/root, which I know is more full featured. Trying to get something to work on inbound... I think I may just be too tired and should probably call it a day and try tomorrow... Unless an expert show up with a magic pill for me so I don't have to think at 7am :)