Create etherX without WAN access but with LAN access

Good night,

For security reasons I wish that a device cannot connect to the WAN but to LAN.

The only way that I have come up with to achieve this is to make an exception to IP in NAT, but I am convinced that there may be other, more pure ways to make a router’s mouth lack WAN but have LAN access.

regards