When the router gateway is on the same address scope as some of the interfaces,
we do not add SNAT rules for those subnets.
For the traffic to pass, we should also add a matching FW rule to allow the
return traffic, the same way we do it for no-SNAT routers.
Change-Id: Ief4519111b20aed43f660c78a461cd208332a502