Question:
Could you just not cofnig an ACL on the inside interface blocking there IP's from using the ports VPN uses? I guess if that are DHCP then this would casue a problem.
I've never done it but according to this Cisco Doc (http://www.cisco.com/univercd/cc/td/doc/product/software/ssr90/rpc_r/21972.htm#xtocid161035)
you can filter on Ethernet MAC with access-lists 700-799
You'd have to do this on the inbound of the inside interface i'd supose.
As i said i've never done it or seen it done so let me know if it works or does not.