OpenWRT as transparent firewall on a NanoPi R5S

I thought banIP set rules in a real firewall. Is that also possible in a filter bridge without NAT, etc.? I was thinking more along the lines of using nftables or ebtables. I'd have to write a script for that, but that should be possible via SSH on the device.

Using KVM is an elegant idea for testing, but I don't want to modify my Open Media Vault on my PC with it. There have apparently been occasional conflicts between KVM and Open Media Vault.

For playing around and testing OpenWRT, I can now use my old Fritz!Repeater 450E, which I got working after a day of working with OpenWRT.