Two subnets on the other side: how to manage it

Site A. “Corporate Headquarters”.
Unfortunately, subnet 192.168.1.0/24.
Site B. Warehouse. Two subnets
192.168.10.0/24, for printers and computers (green)
192.168.11.0/24, for wireless endpoints and equipment (access point management).

IPSec tunnel between the sites, 192.168.1.0/24 to 192.168.10.0/24

New task: allow selective access from 192.168.11.0/24 (reservations + range + ip binding) to 192.168.1.0/24.
Current solution: second tunnel 192.168.1.0/24 to 192.168.11.0/24, firewall rules on site B for allow comunication only for the devices selected.

I’d like to have some other ideas