What to drop - Bridge Interface, or physical Interface ?

Hi folks,

I’ll be stesting that probably tomorrow - but what shall I drop…

for openvpn - I have setup a bridge interface to the Local LAN interface - e.g.
Lan - Ether5 and ovpn are linked to Bridge-vpn interface.

If I now want to add a rule to drop traffic to Lan and ovpn interfaces - is it enough to drop the traffic to the bridge - or shall I drop the traffic to Lan and ovpn ?

Thx