Look for policy routing (not IPsec policy), there are tens of topics here. In short, the principle is that you classify the traffic originated by devices on your LAN by its properties known already before the routing has been attempted (like source IP, source port, destination IP, destination port,...