Access Control of Zerotier

In my Zerotier network, I have 2 subnets, they are and I want to implement an access control strategy for the above two networks. Among them, can access any host at, but cannot access any host at . How should I use Flow Rules to configure it?

I’d probably use the capabilities and tags to create “departments” and not base the rules on IP addresses.

