To be able to block clients from a hotspot (so they don't even get an Ip address) it would be useful to
have address-lists that store mac-addresses. Then one could set up a 3-stage set of lists like the SSH bruteforce recipe
and f course add-src-mac-to-list and add dst-mac-to-list (and hopefully also remove-src/dst-mac-from-list...+1 for mac-address-list in bridge filter/nat and mac-address-list along with ip firewall rule src-mac-address matcher