Hello, try making up groups of all your gateways. Set up a rule to drop ICMP from your vpn network to ip group gateway under LAN Local, That will prevent ping, then you can drop all traffic from vpn network to all other gateway addresses excluding the gateway of your vpn network. This is set up in LAN IN. You need to set up the gateway groups excluding the network required gateway. So if you have 5 networks you will have 5 groups of 4 gateway ip addresses. If you block the gateway of the network it is serving you block all traffic. That is when you drop icmp to that gateway instead. To keep from vpn client from accessing vpn network gateway, you can block port 22, 443, and 80. Which will keep clients out of your gateway’s interface.