Ok Im am no expert for sure, but a simple google for mac filtering with ipfw, first thing I think that would have to happen is to turn on
sysctl -a | grep ether.ipfw
I believe this has to be 1 to do layer 2 checks in ipfw??
I think once you set that then sure you could write your own rules. I would suggest you put in a feature request if you want the gui to be able to do it, or start posting a bounty.