Dropping Eth1 traffic not destined for default gateway

Morning All

Im just flashing a few routers to use as hotspots, and we always run eth1 with a dhcp-client on.

Im sure theres an easy way to drop all authorised hotspot users traffic thats exiting on Eth1 thats not for the default gateway (internet) - ie, we want to drop any traffic sent to the local lan on the same subnet as the eth1 dhcp client.

At present I manually enter a firewall rule to drop all traffic to the local lan once I know what it is, but it sort of defaults the point of having a ready made script with flashfig.

Can anyone offer any advise?

Could you use vlan interfaces to isolate traffic? If not, couldn’t you use a /30 router interconnect subnets between devices? (I’ve never tried that out of DHCP server but it should be possible)