Setup an access list on the router allowing them to communicate in the first place. If that is the 4500 set it up there.
Use UniFi insights to find denied connections and troubleshoot rules, then tune VLANs so cameras and IoT cannot touch sensitive devices.