Flow Rules for Router Setup

Hi,

i have a Zerotier Setup with 3 Routers.

The Router

Router 1). Zerotier ip 172.25.25.10
Subnet on Router
10.0.1.0/24
10.0.3.0/24
Router 2). Zerotier ip 172.25.25.11
Subnet on Router
10.1.1.0/24
10.1.2.0/24
Router 3). Zerotier ip 172.25.25.12
Subnet on Router
10.100.1.0/24
10.100.2.0/24
10.100.100.0/24
10.100.101.0/24

I can reach all networks with each other.
My Question is, What should the rule look like so that the 10.100.100.x and 10.100.101.x network on Router 2 cannot communicate with the Zerotier network?

Thanks,
Sebastian

i Also test it with this rule, but it also dont help

accept
        ipdest 10.100.1.0/24 # opensoc Lan1
	or ipdest 10.100.2.0/24 # opensoc moloch

but i can still access the 10.100.100.1 network.

Thanks for Help,
Sebastian