IP (L3) firewall cannot block communication between devices in the same subnet because that happens on L2. So if the Ubuntu is the only machine connected to some a physical interface of the Mikrotik, you may permit use of firewall also for bridge, and set bridge firewall rules to block it; if some other devices are connected (indirectly, by means of external hub or switch) to the same physical interface of the Mikrotik like the Ubuntu, you cannot block traffic between the Ubuntu and these devices because that traffic won't pass through the Mikrotik at all.
I think you have right.
Mikrotik connected to switch which is connected to server (on this server run the vmware...).
So in this case there is no way to isolate this Ubuntu from other devices on LAN?