If firewall bridge is configured, traffic is always analyzed at IP layer too.
This is because currently sysctl parameter net.bridge.bridge-nf-call-iptables is set to 1
An option for editing this behavior/parameter needs to be included in firewall global-options