Instead of 2 bridges, add all ports to a single bridge, enable the use of ip-firewall in bridging and filter traffic in ip firewall by the use of the in-bridge-port and/or out-bridge-port rule matchers. This will let you control which traffic is accepted or dropped to each port. Alternately, leave the 2 separate bridges, and NAT between the two only that traffic which you want to allow.