Not so easy, first because you need to clarify a bit: what do you mean when you say "doesn't see"?
Are these devices on same physical segment (same LAN)? Then FW would never be
in the middle to control who/what is seeing what
Aside netmask that may help a little providing some kind of segregation, better approach would be VLAN. But again, we are discussing about network stuff which is perhaps not what you do need even if you express it in term of network first.