How to configure domain isolation using ipsec policy?

Hi

We want to configure the domain isolation using ipsec policy in our environment. Our environment is in multi forest architecture.

Can you please help us what are the best practices and how to configure it.

Thanks!