Skip adding ingress discard rule to legacy VPN

Cherry-pick of aosp/3201971 to backport VPN security fix to non-mainline
U devices.

Some legacy VPNs need to receive packets to VPN address via
non-VPN interface.

Bug: 193031925
Test: TH
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:5441470a6a04f36369ec79c3eff3a72fc47ca9e3)
(cherry picked from https://googleplex-android-review.googlesource.com/q/commit:717bb36e5963c2dc4c315b7d58f0c7b3d85fcf31)
Merged-In: If4f6b095a719a0abcb6254c522beac5d45110d4d
Change-Id: If4f6b095a719a0abcb6254c522beac5d45110d4d
1 file changed