you could create a firewall rule in the LAN interface where these devices are.action: rejectdirection: inquick: yesSource: alias for your deviceport destination: ! LAN net Needs to go before the default "allow lan to any"The devices in the same network will go via the switch, not going via OPN unless it's the gateway for the VLANs, so you can still get to them.
port destination: ! LAN net