Only allow certain MAC adress is not working properly

I want to allow only certain MAC adress to have access to my PC network.

I want to block all IN an OUT from every MAC adress except one or two which I want to allow.

I tried a lot with the Global rules and the network zones but it is not really working. The except checkbox is also quite misleading. What is working is to exactly block a single MAC. But not to allow.

Can someone give me a hint?