Via a custom ACL. That is AFAIK not available in the Gui
I do that via a FW alias list containing all the local subnets and use that in the NAT rule pointing to squid as inverted destination.