Best practice for segregated VPN assigned to specific ETH

Hi
Bit of a newbie here… please bear with me.
I have the following scenario:

  • Internet WAN of ETH1. 2 LAN on ETH2 and ETH3


  • SSTP tunnel built from Mk to a server on WAN.

I’d like to have one “classic” subnet on ETH2 with a DHCP range etc for LAN access to the Internet and another segregated subnet with a different subnet bridged to ETH3 that would tunnel through the VPN.
Also if for some reason the VPN goes down I don’t want any traffic to egress though ETH3.

What would be the best practice to achieve this ?