Because internal LAN traffic is going without DFL's control, you can't do it very simple.
DFL provides you two solutions:
1) transparent mode
2) routing (different network from lannet)
Both solutions require to put limited client(s) into separated interface (DMZ, one of LANs on DFL-260E/860E or VLAN) and allow only traffic to WAN, but don't allow (e.g. block) traffic to LAN.