you can do that using Firewall filters
example : if you you want to prevent machine-A from communicating with machine-B & both are at Vlan-X
steps:
1# define firewall filter :
SW1# show firewall
family ethernet-switching {
filter filter1 {
term term1 {
from {
source-address {
machine-A-ip;
}
destination-address {
machine-B-ip;
}
}
then {
discard;
}
}
2# apply the filter to the vlan :
SW1# set vlans Vlan-X filter input filter1;
note : the filter blocks communication from A to B ( not from B to A )