You may be able to change the firewall default to block outbound, then create a rule that allows the LAN ip address range.
https://www.howtogeek.com/112564/how-to-create-advanced-firewall-rules-in-the-windows-firewall/
--please don't forget to Accept as answer if the reply is helpful--