I have a similar set-up
I use a wireless access point that can expose multiple ssid with different vlans (I think it a fairly common feature)
my router runs openwrt and the iot vlan is in a different firewall zone
use wireguard to remotely access the lan zone
deleted by creator
deleted by creator
deleted by creator
deleted by creator
deleted by creator
It’s a very nice rock.