Branch: stable/queens

commit b88ab58daf12337903f3fd8a4ab4c6add6f379cd
Author: Doug Wiegley <email address hidden>
Date: Sat Mar 2 22:35:52 2019 -0700

    When converting sg rules to iptables, do not emit dport if not supported

    Since iptables-restore doesn't support --dport with protocol vrrp,
    it errors out setting the security groups on the hypervisor.

    Marking this a partial fix, since we need a change to prevent
    adding those incompatible rules in the first place, but this
    patch will stop the bleeding.

