Talking with two of extreme pre-sales guys bring a good solution:
s-series L2 ACL (starting with V8.42)!
with a few lines i can allow communication to MAC of L3 Router, ARP, needed Broadcast traffic only and deny all other Client to Client traffic.
Logging function is very helpful to see if ruleset is complete.
Regards,
Matthias