Then get a packet trace of a failing session with tcpdump. You may need to get two, one one the client and one on the server to be able to see which packet isn't getting past the bridge. There are tools to santize tcpdump files if you are paranoid about IP adresses, etc.