PS:
Correction! /etc/rc.local isn't OK. The ARP record needs to be reloaded if br-lan interface is restarted, such as when changing other network settings in WebUI. So only /etc/firewall.user will do.