There might be several way to do it. But i did it this way. Take a look at the image below. Subnet #2 is i believe what you are looking for. The network is fully seperated from all other LAN in the cluster but they also are connected to Internet. The trick is to use a Virtualized Firewall. In my case i used pfSense.