One sided firewall drop rule

Hello,

i got a IPsec VPN Setup with an Mikrotik VM Cloud installation, 3 Lancom´s and a Mikrotik Routerboard.
All 4 are connected to the Mikrotik Cloud with IPsec. At this time they all can communicate with each other between their different networks.
But i want to setup a Firewall Roule on the Mikrotik Cloud that the 3 Lancom´s cant communicate with each other. That every Lancom could only communicate with
my main mikrotik Routerboard. So i set a Firewall rule to block the traffic for example from the first Lancom with the network 192.168.29.0/24 to the second Lancom with the network 192.168.32.0/24. But if i set a Firewall roule with Src. Address 192.168.29.0/24 and Dst. Address 192.168.32.0/24 and the action to drop. He drops the traffic from both sites and not as i thought only from Src to Dst.
Do you have an idea how to get this working?

MFG Start1