I've tried this configuration with a single ip address out of MAIN IP subnet, i also have one inside and it works with the config you mentioned, point to point to gw in the physical interface, and then the first bridge with no bridge port and the route for the first ip , and it works, now...