it only works with public IPs if they are reachable over the default route.. in your case, if you want to make everything on that bridge reachable (modulo firewall rules), use /24. alternatively, use /32 and manually add the required routes inside the container..