How to configure IPS mode with AF-PACKET?

hi jason, I deploy suricata ips at layer 2 on my multi interface compute (named host2).
the network topology like this:

however, I can ping host1 and host2 on host3. but I can not ping host3 on host1 or host2.
Any ideas to solve this problem? thanks