Enable the firewall (note that it has to be enabled on the VM's network interfaces as well as the VM's firewall's [Options] page) and for every network interface add an IPset called ipfilter-netX (X being the interface number) and add the IPs the VM is allowed to use.
For containers this filter will implicitly contain the IP addresses configured on the interfaces via the gui.