OpenVPN Site-to-Site: Allow only specific internal IPs and ports through tunnel

    I am trying to setup an OpenVPN Site-to-Site connection and only want to direct specific LAN IP addresses AND port traffic through the tunnel.  Right now ALL traffic is going out the WAN including internal metrics and alerting.  I want to isolate the 'internal' traffic that doesn't have to be exposed to the WAN to go through the tunnel.

    Both sites are in a CARP configuration.  I am familiar with OpenVPN as we currently have a separate pfSense for our VPN.

    Any suggestions or pointers will be greatly appreciated.

