prevent openvpn client from changing ip of tap device

Solution 1:

Why server-bridge? Why would you use a bridge if you want to implement firewall rules? If you give clients a layer 2 tunnel to work with, then they are going to be able to change their layer 3 addressing.