Even if you are doing B@HWC you can only block mu to mu traffic for end systems on the same controller. We have multiple controllers and end systems can talk to other end systems on the other controller if block mu to mu is on. To accomplish what you are trying to do you can create a rule that denys traffic to the subnet the end systems are on. This will work, I've tried it. They wont be able to ping their gateway but they will be able to traverse the gateway because the gateway is never the destination. These days end systems dont really have to talk to each other directly. If that is true for your network you'll be fine. If not you can make exceptions.