@Derelict:
Yes. I would create a VLAN for the green network. Call it VLAN 20.
Thanks much for the VERY helpful post. I haven't had too much time to work on this yet, but I have made some initial progress. I've actually decided to go with 3 new VLANs:
VLAN 10: RED - No restrictions
VLAN 20: YELLOW - Trusted family devices
– Access to RED net for printers, etc. (I implemented account controls for the NAS to allow backups)
-- Web filtering, with pass rules for Steam and Battle.net (so far)
VLAN 30: GREEN - Untrusted guest devices
-- No access to RED or YELLOW nets
-- Web filtering, HTTP, IMAP, SMTP ports only (80, 443, 465, 993)
Haven't had time to implement the WLANs yet (right now both APs are on RED, using the same 2.4g SSID, and in addition the NT-R66U is using a unique 5g SSID). Mostly using the two APs to extend range. I may use dansguardian filtering on YELLOW and RED instead of OpenDNS--it would be helpful to have all the nets use the DNS forwarder and cache. But I do have OpenDNS working on YELLOW by defining the two DNS IP addresses on the interface page and rejecting port 53 on the firewall page.
Thanks again!