Hi Hartmut
Sure, in its simplest form, here is my lab rule:
I know the article says to allow to the subnets default gateway but I don't see a reason to do that, generally traffic is passing through the default gateway, not directly to it.
I just tested the above in my lab and it works.
-Gareth