I am not aware of full picture of your network but what I meant was why don't you use l2 acl on respective port and choose smac X (some specifc MAC) and dst mac Y which you want to pass thru for this neighbor rest you can drop/deny or visa-versa,more...