separate local and internet traffic. help, this almost solve

Wireless - traffic not count nat + filtered internet drop.
VPN - traffic count fileterd internet accept to PPTP + filtered drop local

I create a VPN, and Wireless on the same profile to one client on the MAC address can enter the internal network and the Internet has on the VPN. if you select a MAC address as the name of it is through the VPN only with login = MAC but the password should be empty(but it is not safe), if you select the mac addres as username and password creates a VPN login=MAC password=MAC (but it is not safe).

  1. How to create a user name and password in the user-manager, to MAC and password were different, and password to enter the client of any other???

  2. How can I make a VPN entered only from that MAC address, which is given to him as a user name???

HELP!!!