omegahost,
Security Policies will only implement L3 firewall rules, you will need to define L2 rules directly via the Firewall -> Ethernet menu.
Note: While you could create a firewall rule with a L2 service in your security policy it is pushed to the L3 section and ignored. I have verified this using NSX-v 6.4.1.