ACL's for very specific subnet isolation

Please note:

Below is a more concise example of using iptables to allow containers/vms of one bridge to talk containers/vms/ on another (specific) bridge:

This solution is probably not as concise as you want; however, it gives you some degree of control.

Does this help?