As to running multiple ssid with different vlans. While this might be possible with something like openwrt or dd-wrt on your old router yours going to use as just AP. If I recall the vlan support on these devices were dependent on the chipset and not all of the routers that run wrt support the vlans.
If you really want to run vlans for your wifi I would suggest you go with real AP with this support, the unifi stuff is quite home budget friendly and support up to 4 different ssids per radio and very easy to setup for vlans on your different ssids. The new AC lite model is only $89 while the pro model is only $149.. I have 3 of these in my house, the lite, the lr and the pro of the new AC line. I run 3 different ssids all on diffferent networks. My normal wifi which is eap-tls for auth (my devices like laptops, ipads, phones all use this), my psk network for devices that do not support eap-tls like my nest thermostat, my harmony hub, nest protect, rokustick, etc. And then your typical other psk authed network that is for my guests.
The unifi AP bring to the table band steering to put your devices on either 2.4 or 5 with the same ssid, they also support Air Time fairness and just recently enabled the DFS channels for 5ghz band so lots and lots of channels available depending on your clients support for these networks. The free controller software you can run also brings lots of insight into your wifi network, what clients are connected to what AP, what speeds they are connected at, errors, bandwidth used, etc. etc.
These wifi networks are all firewalled via pfsense and have varied access into my other networks.
As to blocking ads, yeah pfblocker package makes this pretty simple to do.
As to openvpn, yeah this is few clicks of the wizard to setup on pfsense, I vpn into my home network pretty much every day from work. And yup there is a openvpn app for both ios and android devices that is clickity clickity to use.