Allow only certain MAC/ IP address to access pppoe client devices.

Good Day,

I have been trying to get this right but it seems like I’m missing something,

What I’m trying to achieve is to be able to login to my pppoe client device to be able to change settings ect.

I have managed to do that with an accept rule in the IP Firewall Mangle section.
The big problem is that with this rule enabled all Clients on the same PPPOE profile/network can also connect to each other.

All I need is for only my small pc running air-os which connects to the main RB1100 to be able to login/ping client devices,
the clients should not be able to.

ALL HELP WILL BE APPRECIATED