With my L2TP/IPsec tunnels I can't get proxy-arp working with 7.1beta5, as I can't get ARP from any devices on the local network. Regular websites work just fine and I can connect to the router itself, but nothing else. It's sad that so much stuff is broken in the 7.1 betas and I can't just not use them because they have Wireguard support. The proxy-arp is set on the LAN bridge and I'm using a L2TP road warrior setup.
I haven't tried this myself - I use a different subnet for my L2TP road warrior setup so that I don't have to use proxy-arp in the first place as that is generally the best way to go.
Is there a reason you absolutely need proxy-arp? I understand the frustration about things not working in ROS 7 but the beta is basically an alpha, unlike the 6.49 beta series. You should be able to adjust your setup so that your VPN range does not overlap with your bridge IP subnet and then proxy-arp is not necessary. I agree that it should work, but ROS 7 is still far from stable, and at least proxy-arp is something that you shouldn't absolutely need and can work around. It is a bit of a hack at the best of times - not good practice to use when you can avoid it.