In practical terms, this means that you have to put your Chinese (IoT?) on their own network. You can either have a separate NIC on the firewall, or you can create a separate VLAN on a managed switch.