The fact that the subnets don't overlap would indicate two separate security policies. You need to stop hosts bypassing their restrictions by just changing their IP address.The common way to stop this is to separate the hosts by VLAN. This implements your policy on devices outside the host's control (firewall and switches).