It seems that you simply want to restrict access to devices in 10.147.13.0/24 network from LAN.
You could configure a traffic rule to drop traffic coming from the LAN network of RUTX09:02 to the 10.147.13.0/24 network. For this, navigate to Network -> Firewall -> Traffic rules. Add a new instance (add new forward rule).
- Protocol: any
- Source zone: LAN
- Destination zone: WAN
- Destination address: 10.147.13.0/24
- Action: drop
This rule should drop all LAN traffic destined for the 10.147.13.0/24 network.
You can find more firewall information on the wiki page here.