
Reorder the FW rules on the edge, so that internal & MD proxy traffic will always be allowed, but other traffic will go through the FWaaS rules. In additon support the case of firewall policy with no rules, and do not add the firewall rules if the router has no external gateway. Change-Id: Ia4afad53a4b68f87947eec9d0d25007128b174e9