@Ha Vu, SF-G-2 Could you please look at the following page to check under which scenario your setup would fall? I think you need to configure a managed virtual network to allow only approved outbound and check if it works.
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.