It looks like this can be done via MAC Firewall rules.
MAC Firewall Rules “Firewall”
The ability to allow or deny client access by MAC address ensures malicious or unwanted users are unable to bypass security filters. Firewall rules can use one of the three following actions based on a rule criteria:
● Allow a connection
● Allow a connection only if it is secured through the MAC firewall security
● Block a connection
To view MAC firewall rules:
1 Select the Statistics menu from the Web UI.
2 Select a Wireless Controller node from the left navigation pane.
3 Select Firewall > MAC Firewall Rules from the left-hand side of the controller UI
Reference Manual:
http://extrcdn.extremenetworks.com/wp-content/uploads/2014/01/WM3000SystemReferenceGuide_5.2.pdf Page 469
Doug Hyde
Director, Technical Support / Extreme Networks