I checked and it is (squid -v). Will make MAC rules and test. Also might make a quick web interface to manage
well, you can use mac addresses stored in "hostnames and addresses" panel.. premit them, block any other mac address
please, be aware that would not use iptables (i.e. firewall) to block clients, so external access will be possible..
if you need to block at firewall's level (IOW disable access from some internal clients to WAN), you'd not use squid but work on a masq fragment