You have to segment your network for isolate virtual machines sets.
You have to connect your firewall to all your network segments and define the necessary firewall policy for allow only the required traffic between networks and block the rest.
It is not necessary to create a Proxmox bridge for...