Wireguard VPN - Subnet Remote LAN Restriction

Dear admon,

Thank you for taking the time to review my post.

Currently, my travel router is configured with three segregated networks, each connected to my main router via WireGuard VPN. However, one of these networks should not have Remote LAN access. Specifically, this segregated network should be restricted from accessing local resources, such as the main router's web interface or SMB shares, and should only have VPN access to surf the internet through my main router.

My goal is to allow my family members when traveling abroad, who are part of the segregated network 192.168.12.0/24, to use my main router's IP address to access country-specific website content. At the same time, I want to prevent them from having the rights to open my main router's web interface or access any other remote LAN resources.
Meanwhile, the other two segregated networks from my travel router should have remote LAN and internet access through WireGuard VPN at my main router.

Is it possible to set up this configuration?

Thank you for your time.