Skip adding ingress discard rule to legacy VPN Cherry-pick of aosp/3201971 to backport VPN security fix to non-mainline U devices. Some legacy VPNs need to receive packets to VPN address via non-VPN interface. Bug: 193031925 Test: TH (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:5441470a6a04f36369ec79c3eff3a72fc47ca9e3) (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:717bb36e5963c2dc4c315b7d58f0c7b3d85fcf31) Merged-In: If4f6b095a719a0abcb6254c522beac5d45110d4d Change-Id: If4f6b095a719a0abcb6254c522beac5d45110d4d