Spoofing protection (IOW allowed clients on the private side) on the outgoing is forcing things not right.

Or, to put it another way:

making sure who you are and who you claim to be is the same thing. From an ARP perspective and packet mangling. Usually an "interface rule"