On Fri, Mar 04, 2022 at 09:10:50AM +0100, Marc SCHAEFER wrote: > I found out that if the br_netfilter module is loaded, it works without > the BROUTE. I will investigate if there is a way to do it less globally. Apparently through ip link set dev BRIDGE type bridge nf_call_iptables 1 However, ebtables BROUTE seems incompatible with basic iptables (nft only).