make a vlan even if its just a section of ip that have no access you can indeed do that i personally need help with rules i can do the vlan part easy enough tho. to do a vlan with 1 ip just make the range bigger or set aside 20 or so ip put on vlan (x) then make x have no internet even with out the other machine doing it, you can make it a access rather than a trunk line and just segment it anyway.