Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
If the gateway for the subnet is on the FW (an external device), then you can not enforce policies for the EPGs that belong to the BD which in turn does not own the gateway IP. You can enforce the policy only when the BD owns the gateway IP.