I don't believe that can be done with FTD.
On FTD, your standard Access Control Policies and Prefilter policies all affect traffic THROUGH the device - not traffic TO the device.
On ASA we had the option of adding "control-plane" keyword to an ACL entry but that option is not available on FTD.