If you set the TTL of your IoT devices to 1 or, if needed 2, the device can never communicate on its own initiative with a remote server. You are still able to control these devices from your LAN

