Go to User&Devices > Device > Device Groups and Create New and create a "blockedMac" Group Go to User&Devices > Device > Device Definitions and select Create New (or look if it's already listed if you have Detect and Identify Devices on on the interface) Now go to Policy&Objects > Policy > IPv4 and Create new
Incoming Interface: Lan Source Address: all Source Device Type: "BlockedMac" Outgoing Interface: Wan Service: All Action: Deny