Hello @mhadley
Assuming that you have the Z3 configured for VPN full tunnel to one of your Hub MXs, the traffic from the Users would not be hitting L3 firewall rules on the MX as it will traverse VPN due to full tunnel. That is probably why the users are able to access other IPs on your LAN. For traffic across VPN, go ahead and configure the Outbound VPN Firewall rules in the Security & SD WAN -> Site to Site VPN page. Please configure the rules keeping in mind that the S2S VPN rules are applicable Organization Wide. So, please configure the Deny for specific Source subnets inorder to avoid any unexpected issues.
Please let me know if you have any further questions. I will be glad to assist you.
Regards,
Meraki Team