It forces any bridged traffic to also pass through IP firewall chains
https://help.mikrotik.com/docs/display/ ... dgeForward, this is only required if you wish to apply firewall rules, where bridge ACLs are insufficient (e.g. as they are stateless), or queues to this traffic.
It reduces performance as there is more processing involved, and can have unintended consequences if the traffic accidentally matches rules due to poorly specified matching. Also note it only apples when the bridged traffic is not hardware offloaded as this never reaches the software bridge
https://help.mikrotik.com/docs/display/ ... adedPacket.