Block trafic from WAN to a specifc IP

Hello,
I have a container running on 192.168.0.69 and a I want it to be accesible only from local network.
How do I add a rule to block wan access to this ip?

The real question is Why and How t is accessible from WAN??

/export file=anynameyouwish ( minus router serial number and any public WANIP information )

nothing…