Nemyslim, ze je to uplne OK, ale celkom to chodi : S tym, ze na ether3 je PC, ktory sa nesmie dostat do siete na bridge1
chain=forward action=accept in-interface=bridge1
chain=forward action=accept connection-state=related in-interface=ether3
chain=forward action=accept connection-state=established in-interface=ether3
chain=forward action=accept in-interface=bridge1 out-interface=ether3
chain=forward action=drop in-interface=ether3 out-interface=bridge1