Regardless of if this is remote access or IPsec VPN, you can disable the access control policy bypass in which case you would need to create access rules on the interface that the VPN is terminated on (usually the outside interface). Doing this will allow you to limit what access the users at the remote site can access in your local LAN. To do this you need to un-check / un-select the Bypass Access Control Policy for decrypted traffic (sysopt permit-vpn) when setting up the VPN. It can also be disabled after setup if needed.
Please remember to select a correct answer and rate helpful posts