tomilius, ebtables+netfilter patches makes bridged packets visible to iptables. that's why I'm talking, that firewall does not expect this. I've ported this patch and ebtables, but then Snufkin found, that this breaks internal traffic.
Read this: http://ebtables.sourceforge.net/br_fw_ia/br_fw_ia.html

and check this as well
http://ebtables.sourceforge.net/br_fw_ia/PacketFlow.png