ACL on RB260GS (allow only pppoe)

SFP port and port 1 - uplink (pppoe server)
Ports 2-5 - pppoe users.

I need to allow packets from the pppoe server (from the SFP port and port 1)

and to prohibit users to everything except pppoe sessions.

SFP port and port 1 - trunk: vlan 2 - users (+ pppoe server); vlan3 - management.

setting up trunks I understand.
But with ACL setting can`t understand.

screenshots of the settings in the attachs.