The VPNaaS driver didn't use the correct groups for source/dest in
added firewall rules. This patch fixes:
- Duplication in groups ids
- Support for service subnet local ids
- Deletion of the created groups
Change-Id: I5c9fd8d9a4f7f7c94ac6cba7eaa159078f28717b