I have a router running asuswrt-merlin so I have access to ssh/iptable rules. Is there a way to make a device not able to access an external network or only allow the IP to connect to another IP e.g. 192.168.0.2 -> 192.168.0.3?

I don’t have a router/switch with custom vlan capability, so I was wondering is there another way to do this?