Two subnets on the other side: how to manage it

Site A. “Corporate Headquarters”.
Unfortunately, subnet
Site B. Warehouse. Two subnets, for printers and computers (green), for wireless endpoints and equipment (access point management).

IPSec tunnel between the sites, to

New task: allow selective access from (reservations + range + ip binding) to
Current solution: second tunnel to, firewall rules on site B for allow comunication only for the devices selected.

I’d like to have some other ideas