Security groups - how to block fixed network?

Hi!
I’m using OpenNebula-5.2.0.
I’d like allow traffic from vm to 0.0.0.0/0 except local lan. I can allow outbound traffic to all but I don’t see how to add rule to reject traffic to given network. I’m missing possibility to set policy allow/reject inside rule definition.