Done.
By the way, here's the current network setup:
I have already created a group policy for D2.
As mentioned earlier, my goal is to block internet access for both D1 and D2 clients, while still allowing them to ping each other internally.
Current situation:
Clients in both D1 and D2 can access the internet and ping each other at the same time.

Now it is time to apply it to the VLAN interface ? And any screenshot or steps?