Create a network group, for example "my-VPNdoamin", add in this group all current and later created subnets.....which you are already doing....
Think in subnet terms and not in static IP terms...... the 2 subnets have to still be defined at the remote site too...
So when the tunnel negotiate is negotiated in subnets terms....not single hosts, on both side local and remote.
Then use security policy access control to "allow" or "deny" specific hosts access with service and application.
Yes, you can still create the VPN tunnel in indvidual single hosts (inside the VPN Domain group)....
but you have make sure every single host you add on your side HAS to be DEFINEDand added on the remote side too....
VPN tunnels parameters have to match exactly on both sides.....