Yeah, the VLANs on the consumer stuff failed hardcore with what I wanted.
So basically what I'm trying to do is this: the different networks are physically separated. In other words, the AP for the home network runs just that network, and the AP for the guest network runs only that network.
So lets say the home network would be LAN1 - all the APs and switches connected to this are only for the home network, which means full access to everything on this network as well as to WAN
and OPT1 which is connected to the guest AP which runs only 1 SSID for the guest network and has no other physical connections, it also needs to connect to WAN
But I don't want LAN1 to be able to talk to OPT1 at all.