N900 lan to lan FW

is there any way for me to limit a lan machine access to other lan resources ?

I was trying in the firewall section to create a rule that has a src and dst address pointing to the LAN. Unfortunately it won’t save, the error stating that src and dst cannot be the same.

No, because the filtering is only done at the router level (or “Layer 3” network address).   The switchports aren’t subject to filtering because they’re switch ports (Layer 2 network), not router ports.