Use VPN to grant access to internal IoT subnet

I've set up VPN (L2TP) on my Unifi USG and it works flawlessly when away.

I want to be able to connect the VPN when I'm at home as well and grant access to my IoT subnet only from the VPN subnet.

Is that possible?