I would recommend to use a new partition, vlan and route domain.
In general you would on each device for your device group:
Create new partition 'Internet'
Move to partition 'Internet'
Create the new vlan(s)
Create the new Route Domain ID=3, Strict Isolation, Partition Default Route Domain, selecting the vlan(s) for it
Create the new self IP(s), local (on all devices) and floating (on Active Device)
Add default static route on the active device.
Synchronize the configuration changes from Active Device.
You can then create any object from the new partition and it will automaticaly be associated to the new route domain and be isolated from objects configured on the default partition(Common) and route domain(0).
Hope that helps.