You can always block access with the firewall feature of ZS. However providing your clients your ISP’s DNS server instead of yours is not exactly a security technique.
My suggestion is to provide to your clients your DNS via DHCP (to reduce the internet utilization by caching) and deny access to your internal network as you wish.