Adding a new configuration to let the admin control if the edge firewall
rule will see the external addresses or internal ones, thus controlling
the order of implementation.
The new parameter firewall_match_internal_addr is True by default
so it is backwards compatible.
In addition, adding an admin utility to change this flag across all
existing nat rules.
Depends-on: Ia34e42a94c10bd3f12ebc658939ed826af53658c
Change-Id: I29e7acc03bf6b845d9a727cf075cbe2b0609af34