Hi,
I didn´t tested the equipment, but i think its configurations are made in web interface. ( I think you can add access lists on the web gui of this router model)
You can create access lists and associate to the outbond interface (WAN interface) to only permit the subnet that is able to connect to wan and deny the rest of the hosts.
To get a easy management create vlans with DHCP pools to isolate the hosts with access from the hosts that you don´t want access to WAN, and associate the vlans in the switch ports.
In this way you don´t need host static IP addresses
Best Regards,