> Many kernel extensions are closed source, but that's not relevant here.The side effect is encountered when filtering on the MAC source in the iptables FORWARD
The side effect explained here occurs when the netfilter code is enabled in the kernel, the IP packet is routed and the out device for that packet is a logical bridge device. Using the MAC module extension for iptables.