Hi!
try using 'vmbr0' in both iptables commands, so that your traffic gets masqueraded through vmbr0 (which is, I assume, what you want). Because in the current setup with the 'bridge-ports eno1' the whole traffic flows directly to eno1 (which has the same ip address as vmbr1, as it's the bridges slave port).