Bridge NAT

Hi,

I’ve a tunneled network where I have a headend MT-Router which should control
all Ethernet-Traffic between connected Devices.
The whole Network is EOiP-Tunnelled to a bridge on this router.

To allow limited traffic between devices on this network I have a Bridge-NAT Rule
to hand over the MAC-Address of the central router for every ARP-Request.

Just doing one Bridge-NAT Rule does not work. Seems the package gets NAtted but
also gets through unnatted??? I have to do an additional Bridge-Filter to drop
the packet.

Is this normal behavior or a bug?

Stefan