Create a separate group on the concentrator for just this person, and set up his client to connect to that group.
Create a rule (under Config - Policy Mgmt - Traffic Mgmt - Rules) that is Inbound/Forward, Source of Anything, Destination of /0.0.0.0, dest port TCP port 25. Create another rule, it can be left at the defaults which is Inbound, Drop, Source of anything, Dest of anything. Create a filter (under Config - Policy Mgmt - Traffic Mgmt - Filters) with default action of forward and add both your new rules to it, making sure the rule that allows access to the host mail server is ABOVE the default rule that will drop everything else.
Modify the group you created for this one user and under the General tab, apply that filter to it.
This should be all you need to do. Test it first to make sure.