limit internet access

Hello,

I am using MikroTik cellular modem to install on site. We use AWS VPN to connect cellular modem, however, I don’t want site PC or some other device to access internet, how can I do it?
also I have other request, I have one pc on site that installs a software with online license, but I want to block that PC internet access but I wan to allow software license site available for this PC to access internet, is it possible to set?

Thank you

On your forward chain (in pseudo code):

  • allow access to specific site (by IP address?) for single device (by fixed IP address?).
  • drop everything else