firewall: fix inbound IPv6

While writing go/fibercl/83393 I forgot to add the wan- chains to
ip6tables, which effectively disabled inbound IPv6. This went
unnoticed to me because inbound IPv6 is broken in NYC.

I could have seen it from rejected icmpv6 echo replies, but didn't.

Fixes b/34340805.

Change-Id: I5f9ea5d191f8ea7eb96342b0c1b996d9784967f5
1 file changed