[neutron][security groups] Drop egress traffic to specific subnets


I am looking at the docs in here:

and I find:

> For egress traffic: Only traffic matched with security group rules are

So we currently have the default security group rule allowing all traffic
to everywhere.

We would like to prevent egress traffic from our VMs into a couple of
internally reachable subnets in our deployment. Is there a way to achieve
this in OpenStack?

Many thanks,
