Depending on the IPX encapsulation, you can try this (tested on a Cat 3550) :
- create a "MAC extended ACL" filtering on the 8139 EtherType
- apply this ACL on the access ports
This should block "Ethernet2" and "SNAP" encapsulated IPX packets without altering other protocols.