Ho would you go about preventing the internal apis from getting accessed directly without routing requests through the api gateway? We would like to enforce all requests to go through the api gateway only.