guess the simplest way would be to create a new vmbr interface, without any physical ports attached, and hook the metasploitable/kali only to that bridge
(if you have ip_forwarding configured (nat-setup, routed-setup, other reason) you need to configure some firewall rules)
as an alternative configuring the firewall would also work.
Test your changes afterwards - then you know that it works correctly
hope this helps!