How to prevent traffic between LXC on bridged network?

Hello,

I have a number of LXC on a bridged network. I'd like to restrict network access for those LXC in such a way

  1. outbound traffic is allowed
  2. one internal IP may be reached
  3. all other traffic is dropped
Can this be done w/ the Proxmox 4 firewall? Or do I need to add custom iptables rules for this? Regards

Christian