ACL an Isolation on CRS with switch feature

Hello,

I have a question about a CRS212.
Here I would like to set ether1 as uplink and set sfp1 - sfp10 as customer ports. The customers should with max. a CPE can go online via pppoe. The customers have to their CPE under circumstances still medienwandler to the router in between.

I would like, that the customers of course not see each other and even just PPPoe disc. and Session can transmit. Also, a maximum of 1 CPE per connection should be able to run.

How can I just allow PPPoE and set the “isolation”?
Do I have to make a “drop all other” entry in the ACL?

thank you
Christian