Zigbee devices are not connected to the internet, so no idea (or no way, rather) to block then from the internet.
No idea why you would want to block HA from your own network.
Making your HA public on the internet is another case, but that requires you to take extra actions m, like setting up port forwarding in your router.
What is more important at the moment is your amount of ram in the NAS box.
2Gb is just not enough to run a HA setup in a VM and NAS service at the same time, so make sure you get it upgraded to 6Gb.