It looks like an arp scan is being performed all the time…
One of my firewalls notoriously detects this traffic from the bridge as ARP spoofing.
High three-digit and sometimes even four-digit amounts during the 24. Nothing else behaves like this except ZBBridge-P.