Via SD-WAN with other branches/spokes and Hubs, Client VPN or Third Party VPN?
If via SD-WAN, Security & SD-WAN -> Site-to-site VPN -> Site-to-site outbound firewall.
By configuring a "inbound" policy destined to your desired branch or branches, you effectively have an "incoming" filter, even with it being blocked on outbound at the other sites. This is due to the fact that the policy is applied to all firewalls in the org