If you are intending to bridge the clients into those separate networks, then it will require one server per network.
If you are only looking to limit traffic, that could be accomplished with some work with overrides, rules, and so on, but it's still best to use separate servers (each with its own different CA structure) for complete isolation.