I am based in Germany and have a bit of an interesting setup for a 3 room apartment. I have a modem connected to my DSL internet, then a mini pc acting as a OPNSense based firewall, a managed Switch (TP-Link TL-SG108PE) and two wifi access points (Netgear WAX615 and NETGEAR WAX214). Currently every device is getting a 192.168.1.0/24 ip address which should be my main ip adress pool for my own devices that should be able to interact with each other. I want to also have external devices from friends inside my network, but on a different subnet 192.168.4.0/24 and they are not allowed to interact with any of the devices of the network but with the internet. This subnet I have already setup on my OPNSense as a VLAN with the tag 4. Now I would love for one wifi network (and one other port of the switch) to send every new connection into the private VLAN 4 subnet and for the other wifi network (and the rest of the ports on the switch) to send every new connection to the default ip address space. I haven't done any tweaking on the switch setup and the wifi access points (except setup the two networks with basic settings), therefore everything goes into the default ip address space.
This is what the switch configuration looks like:
And this is what the wifi setup of the private wifi network looks like on one AP:
And this is what it looks like on the other AP:
If you need any additional infos or already know how I can achieve this then I would love to hear your thoughts. Thanks!