Add TCPMSS rule when setting up VPNs

Third-party VPNs use policy routing to reroute Chrome/chronos traffic
through the tunnel.  This causes the MSS on TCP SYN packets to reflect
the MTU from the original interface, not the tunnel MTU.  Add a firewall
rule that fixes this.

TEST=manually verify MSS via tcpdump
TEST=`FEATURES=test emerge-link firewalld`

