Security groups - how to block fixed network?

I’m using OpenNebula-5.2.0.
I’d like allow traffic from vm to except local lan. I can allow outbound traffic to all but I don’t see how to add rule to reject traffic to given network. I’m missing possibility to set policy allow/reject inside rule definition.