This change leverages a new NSX client method, patch_entries.
This method does not require all rules to be in the request body.
We can therefore save a DB operation, and submit a much smaller
payload. NSX responses are also much faster.
In addition, this routine ensure the DB record for a security
group rule is removed if the creation of the same rule fails at
the NSX backend.
Change-Id: I5c97c3042f8f740cac211314e11ce01e03beaa7e