You would implement this using firewall rules. There's different places you can apply them, but the most logical for what you're trying to achieve would be "Site-to-site outbound firewall" rules. These are configured under "Security & SD-WAN -> Site-To-Site VPN". Take a look at the below link for some extra info and examples Site-to-site VPN Firewall Rule Behavior - Cisco Meraki
... View more