Postado originalmente por
netdovale
exemplo
interface bridge filter add action=drop in-interface=etherX out-interface=etherX chain=forward
Basta alterar o "x" para as ether que quer bloquear.
Minha configuração aqui ficou.
0 chain=forward out-interface=ether3 action=drop in-interface=ether2
1 chain=forward out-interface=ether4 action=drop in-interface=ether2
2 chain=forward out-interface=ether5 action=drop in-interface=ether2
3 chain=forward out-interface=ether2 action=drop in-interface=ether3
4 chain=forward out-interface=ether4 action=drop in-interface=ether3
5 chain=forward out-interface=ether5 action=drop in-interface=ether3
6 chain=forward out-interface=ether2 action=drop in-interface=ether4
7 chain=forward out-interface=ether3 action=drop in-interface=ether4
8 chain=forward out-interface=ether5 action=drop in-interface=ether4
9 chain=forward out-interface=ether2 action=drop in-interface=ether5
10 chain=forward out-interface=ether3 action=drop in-interface=ether5
11 chain=forward out-interface=ether4 action=drop in-interface=ether5
Todas as portas falam com a ether1, mais não falam entre si.
eu acho importante tambem add estas regras
add action=drop chain=forward comment="Netbios" disabled=no dst-port=135-139,445 \
ip-protocol=tcp mac-protocol=ip
add action=drop chain=forward disabled=no dst-port=135-139,445 ip-protocol=udp \
mac-protocol=ip