Waldek,
Have you enabled connection tracking for the relevant bridge/VLANs/tunnels, etc. that pass traffic (as this is disabled by default on some systems for non-masqueraded traffic)?
In addition, is your default iptables forwarding policy REJECT or DROP, instead of ACCEPT?
73,
Lynwood KB3VWG