how to route\block l2tp server ?

Hello ,
I have a l2tp server that give address pool of 192.168.0.0/16
for normal reason I gave the local address for all clients 192.168.254.254 (which is the server)
my problem is that when a l2tp client is connect , he can ping and also connect to the other clients that are on line
is there any way to cancel\block this ?
I want the server to be able to see all the client and connect to them\send files
a client can’t do nothing in the network - just get an IP ,allow only ping to the server
some clients will be able to have “admin” setting - so they can ping the all netwrok \ and send files \ connect remote …

what do I need to do ?
blcok something in the firewall ?

Thanks ,