Allowing IPV6 traffic to device with dynamic IPV6 prefix behind firewall

Of course you can with a bit of scripting. And it consumes less resource than putting something like dst-mac-address in the firewall rules, because the Neighbors table lookup doesn't have to be performed on every incoming connection, but only periodically by the scheduler. You can let the scheduled script maintain the address lists with the SLAAC addresses of the devices. Here is my scheduled script:

:local macAddresses {{"TV";"04:4E:AF:XX:XX:XX"};{"TV";"84:C7:EA:XX:XX:XX"};{"XBOX";"B8:31:B5:XX:XX:XX"}};
:local defaultTimeout "2h";
:local cleanupTimeout "5m"
:local prefixLength "/128";

/ipv6/neighbor/remove [find dynamic !mac-address status="noarp"];

/ipv6/firewall/address-list
:foreach item in=$macAddresses do={ 
    :local listName ($item->0);
    :local macAddress ($item->1);
    #:log info "$listName with MAC $macAddress";

    :foreach neighbor in=[/ipv6/neighbor/find mac-address=$macAddress] do={
        :if (!([/ipv6/neighbor/get $neighbor address] in fe80::/10) && ([/ipv6/neighbor/get $neighbor status as-string] != "failed")) do={
            :local deviceIPv6 ([/ipv6/neighbor/get $neighbor address] . $prefixLength);
            #:log info "Found address $deviceIPv6 for $macAddress";
            
            # remove old address list entries
            :local oldEntries [find list=$listName address=$deviceIPv6 timeout<$cleanupTimeout timeout>"0m"];
            :local hasOldEntries ([:len $oldEntries] > 0);
            :if ($hasOldEntries) do={ 
                #:log info "Removing old address list $listName entries for $macAddress with IP $deviceIPv6";
                remove numbers=$oldEntries;
            };
            
            # add entry if not already present
            :local activeEntries [find list=$listName address=$deviceIPv6];
            :if ([:len $activeEntries] = 0) do={ 
                :if ($hasOldEntries) do={ 
                    #:log info "Refreshing address list $listName entry for $macAddress with IP $deviceIPv6";
                } else={
                    :log info "Adding new address list $listName entry for $macAddress with IP $deviceIPv6";
                };                
                add list=$listName address=$deviceIPv6 timeout=$defaultTimeout comment="Device $macAddress";
            };
        };
    };
};

The scheduler interval just needs to be shorter than cleanupTimeout (I have it set to 4 minutes). $macAddresses has the MAC address -> address list name mapping.

The firewall rules just make use of the address lists.