How to VPN site to site for Virtual Rack

Dear Community,
I’m using CCR1009-8G-1S-1S+ to manage my infrastructure in the datacenter (/30).
behind all those public IP, I have a server;
All those servers are using the same local range (10.94.106.0/26).

My new challenge is to get a virtual Rack behind one of them.
I mean : a public IP with mutliple forwarding rules for differents servers
all of them in a different range (192.168.1.0/24).

Then I have to organize a VPN site to site from two site to this Virtual Rack.
Each remote office will use a RB2011UiAS.

Questions :
Do I need to put a RB2011UiAS in the Rack to be sure Virtual Rack is unable to rach other servers ?
or do I need to dedicate 2 ports on my CCR1009 for this Virtual Rack ?

Thanks for your support;
If you have some feedback about your experience for this kind of challenge, it is welcome :slight_smile: