More easy and simple way to disallow connecting to the internet using MIKROTIK LAN IP range + Gateway + DNS and Allow internet connection only for connected PPPOE users:
Load winbox console and set the following:
First step:
IP/Pool/Add
Name: PPPOE-Pool
Address: 10.20.30.1-10.20.30.254 ( You can use any range you like )
Second step:
PPP/Profiles/Default
Local address: 192.168.1.1 ( Mikrotik LAN interface IP )
Remote address: PPPOE-Pool
Third step now lets do NAT for PPPOE users only:
IP/Firewall/NAT
Action: masquerade
Chain: srcnat
Src.Address: 10.20.30.1-10.20.30.254
OUT Interface: WAN
Final note:
In this way whatever the client will put ip without connecting to the PPPOE, will not able to use the internet
Hope this small short tutorial clear many people mind and specially those who regret to tell me how to do this. God gave us a brain to use it ...