Hello Andrey,
I just found a solution for my problem.
First I ensured that ip_conntrack was enabled for VE0.
Then I added the following iptables rule, and now it works fine:
iptables -t nat -A POSTROUTING -d 192.168.255.0/24 -j MASQUERADE -o eth1
Do you see any disadvantage in that way?
Christoph