I've only ever used the documentation off the sourceforge site..
http://ebtables.sourceforge.net/documentation.html
It's quite complete..
There's also this pdf
http://www.spenneberg.com/talks/linu...bridgewall.pdf
The
basic concept is for ebtables to DROP everything and for the nf-bridge to ALLOW everything.
This passes packets into the netfilter system.
Anything netfilter passes will end up back on the wire.
If ebtables ALLOWs anything, you will get 2 copies of it, one from ebtables and one from netfilter..