It sounds like your best option if your MX is also acting as your switch is to do the following. Enable VLANs under routing of the addressing and vlans tab. (Make sure the current vlan is still setup properly afterwards, Check DHCP and make sure it is proper as it was before also.) Create a new VLAN/Subnet for this specific device. Change the interface that the device is connected to and give it the native VLAN of the new VLAN you have just setup. Setup DHCP also so the device grabs proper IP and DNS. After this and the device is up and working properly... You can then go into firewall rules and create rules to block the device/subnet from communicating to the other devices/subnet that you are trying to achieve.
... View more