Yes indeed
For example, activate the FW for VM (Input Drop - Output Accept) -
Then allow incoming connections for some IP ranges (RDP, SSH, Zabbix monitoring...), and doing it for all VM/CTs
This is the reason why I thought datacenter rules with security groups should do the trick