If they’re on the same broadcast domain you can’t filter on the router. On Ethernet broadcast networks clients on the same broadcast domain talk to each other directly, without involving the router. With that many users I’m sure not all of them are bridged to the router, and some can reach each other directly through a switch.