I have complained that the L2 LAN Isolation feature is all or none. I ran into the same issue you are having, where I only need a single client to be able to do some L2 stuff, but couldn't. Ended up having to either allow L2 or create a new SSID for just that client. Not optimal in either solution.
Make a Wish is the only thing you can do at this point. Hopefully the more of us that do it, the more they notice that they need to fix the original implementation.