If you want to prevent local traffic you need an alias containing private networks.Then allow all with destination !private