Block LOCAL IP address using GWN7000


I have a network on using non-Grandstream equipment. It is my MAIN network where the the internet is supplied with an office full of computers.

Ok, I plug a GWN7000 into a switch, and let it use a network range of

I want to accomplish TOTAL isolation from the 2.1 network from the 1.1 network.

So if I want to TOTALLY BLOCK for example, how would I do this. I tried everything in OUTPUT and INPUT firewall rules, and I could still ping the address. IT did NOT block it.