Вот конфиг:
Bridge table: filter
Bridge chain: INPUT, entries: 1, policy: ACCEPT
--logical-in br0 -j ANTISPOOF_VPS
Bridge chain: FORWARD, entries: 2, policy: ACCEPT
--logical-in br0 -j ANTISPOOF_VPS
--logical-out br0 -j ANTISPOOF_VPS
Bridge chain: OUTPUT, entries: 1, policy: ACCEPT
--logical-out br0 -j ANTISPOOF_VPS
Bridge chain: ANTISPOOF_VPS, entries: 16, policy: DROP
-i eth0 -j RETURN
-p ARP -s 52:54:00:12:34:56 -i test0 --arp-ip-src 198.18.12.17 -j RETURN
-p IPv4 -s 52:54:00:12:34:56 -i test0 --ip-src 198.18.12.17 -j RETURN
-p IPv6 -s 52:54:00:12:34:56 -i test0 --ip6-src 2a01:d0:c353:183::17/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff -j RETURN
-p IPv6 -s 52:54:00:12:34:56 -i test0 --ip6-src fe80::5054:ff:fe12:3456/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff -j RETURN
-o test0 -j RETURN
-p ARP -s 52:54:00:78:22:22 -i alpine --arp-ip-src 198.18.12.18 -j RETURN
-p IPv4 -s 52:54:00:78:22:22 -i alpine --ip-src 198.18.12.18 -j RETURN
-p IPv6 -s 52:54:00:78:22:22 -i alpine --ip6-src 2a01:d0:c353:183::18/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff -j RETURN
-p IPv6 -s 52:54:00:78:22:22 -i alpine --ip6-src fe80::5054:ff:fe78:2222/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff -j RETURN
-o alpine -j RETURN
-p ARP -s 88:92:00:48:4C:21 -i veth0 --arp-ip-src 198.18.12.16 -j RETURN
-p IPv4 -s 88:92:00:48:4C:21 -i veth0 --ip-src 198.18.12.16 -j RETURN
-p IPv6 -s 88:92:00:48:4C:21 -i veth0 --ip6-src 2a01:d0:c353:183::16/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff -j RETURN
-p IPv6 -s 88:92:00:48:4C:21 -i veth0 --ip6-src fe80::8a92:ff:fe48:4c21/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff -j RETURN
-o veth0 -j RETURN