Just create an alias with all RFC1918 networks:192.168.0.0/16172.16.0.0/1210.0.0.0/8Add at the end of guest and iot rules add:block dst RFC1918allow dst allOr make it one rule with:allow dst not RFC1918This example assumes you are not using any public ips for lan and no IPv6.