ipfw: forbid adding keep-state rules that depend on tablearg
tablearg value is determined after making table lookup. When we
applying rule action that uses dynamic state, such lookup was
not done and thus rule action can not determine what table and
what value should be used as tablearg.
To prevent this add check for such rules and return error when
they are added.
Obtained from:  Yandex LLC
Sponsored by:   Yandex LLC
Differential Revision: https://reviews.freebsd.org/D51458