think current design is CPE puts those IP addresses into the same routing
table. CPE will search the routing path using CPE’s routing table first when
there are traffics from LAN side, that’s why we can access hosts from LAN to
LAN. So I don’t think we can have a method to prevent it now.