Hints re different IoT clients

Hi

Looking for advice / hints on how to best manage different IoT devices:

  1. the ones that need to access WAN
  2. the ones that need no access to WAN, but need to have "Client isolation" unchecked on the wireless so that I can control directly from my phone while on the same WiFi;

My [clumsy] solution was to have 2 SSIDs (both on 2.4Ghz radio): one with clients isolated, another with clients not isolated. Both SSIDs linked to the same IoT VLAN. Then I need to keep my phone on the second SSID to be able to "talk" to the devices which are not isolated.

I don't particularly like having extra SSID and also making the phone reside in 2.4GHz, which is somewhat crowded in my location, but cannot think of a good alternative. I would happily place the phone on 5Ghz Guest network and reduce the number of IoT wifi networks, but how do I then access those local IoT devices from the phone?

Create separate guest subnets.

I am not sure if I got the idea...

One guest network with internet, other guest network without internet, 3rd for human guests...