You likely have a policy from internal zone to untrust for any source to any destination.
You can simply change the source to the permitted addresses is you want to deny internet access entirely to the other ip subnets.
You likely have a policy from internal zone to untrust for any source to any destination.
You can simply change the source to the permitted addresses is you want to deny internet access entirely to the other ip subnets.