> > I tried to set BROUTING-specific rules using both ntf and iptables > > version of ebtables but didn't succeed. > > Right, this isn't implemented at the moment, > this facility is very much bridge specific. > > What is your use case? > It might help figure out how to implement this properly. The use case is brouter with DROP default policy and some ethertypes and ipv6 addresses allowed to the bridge interface.