I'm not sure what your question is. If your topology is Internet[UTM][Switch]LAN, then the traffic between devices on the LAN doesn't pass through the UTM without some tricks that a technically-savvy person could easily get around.
To restrict client access within a LAN (single subnet) to specific MAC addresses you have to filter the MAC's at the switch level. To get that capability in a switch you are looking at needing a smart switch or a managed switch, your typical $50 8 port switch from Linksys or DLink just won't cut it.
If you wish to restrict access across separate networks (multiple subnets), the UTM can provide the filtering.