VPN + VLANs / different sites

Hi, the following problem:

Site1:
L2TP/IPsec-Server
VLAN11
VLAN12

Site2:
L2TP/IPsec-Client
VLAN11
VLAN12

How can I achieve that form Site1 to Site2 and vice versa only VLAN11 can communicate with VLAN11 (and VLAN12 with VLAN12). There should not communication between VLAN11 and VLAN12.

Create on firewall-> filter rules a rule to drop or accept traffic depending of incoming or outgoing interface