Add a function for defining standard rules on a chain: currently it only
provides fragment-handling policy.
The fragment policy is to pass fragments unmolested, except for TCP. An
IP stack which can't reassemble fragments safely needs more protection
than we can provide here.
Note that this only affects `inbound' chains. The forwarding rules
don't usually work at the level of individual ports, so this is OK; the
ones that do have been nobbled to refuse IP fragments.