Hey @Aondio_Carlo ,
If I understand right, you have a layer 3 device between some clients and the MX? In that case you should be changing the way the clients are tracked from MAC to IP.
If there's an L3 device in between then all the clients will appear to come from the same MAC, so applying policies ot MACs won't work as intended.
For the MX, you really don't want to have a mix of directly connected clients, and L3 separated clients. Try to keep it to one or the other.