What you could do is to setup a virtual machine as a NAT router/firewall (e.g. pfSense). Create a second vSwitch (without physical uplinks) to which you connect the VMs, and connect the router to this vSwitch as well as to another vSwitch with the connection to the Internet.
André