Spoofing protection (IOW allowed clients on the private side) on the outgoing is forcing things not right.
Or, to put it another way:
making sure who you are and who you claim to be is the same thing. From an ARP perspective and packet mangling. Usually an "interface rule"