I think this may be the compromise I go with, because VLANs seem like more complication than I want to get into.
The real priority is keeping the main and GUEST isolated from one another.
Client isolation on the GUEST network would be nice, but is contrary to having those devices all be able to reach a printer, so I guess I'll have to disable isolation if I'm unwilling to set up a VLAN.
Exactly. But to be clear, I believe if you enable intranet on the stock guest WiFi network then every client/device will be able to see each other - complete co-mingling like it’s just one network - so no need for even a second printer.
I think a VLAN is the only way to set up a guest and main network separate from one another and NOT have client isolation between devices on the guest network.
It’s easier for me to articulate with a drawing, but I’ll try with an analogy:
What you want is this:
Aquarium A - all the fish are swimming together in a glass bowl - they can only see other fish in the same bowl and can’t see or reach Aquarium B
Aquarium B - all the fish are swimming together in a glass bowl - they can only see other fish in the same bowl and can’t see or reach Aquarium A
^ I believe the above scenario can be achieved by VLANs
What stock guest WiFi does is this:
Aquarium A - all the fish are swimming together in a glass bowl - they can only see other fish in the same bowl and can’t see or reach Aquarium B
Aquarium B - houses several fish (same water throughout the bowl = World Wide Web internet access), but each fish in the bowl is inside of its own glass cage/container/partition. None of this fish inside of Aquarium B can see other fish in Aquarium B, and they can’t see aquarium A either.
If you enable intranet access on the guest WiFi, there’s just one bowl full of water that all the fish swim in - but there’s a lid on the aquarium jar top with two openings/holes - one hole is called “main” and the other is called “guest.” There’s no security with this method (a mean fish that entered through the “Guest” hole can attack an innocent fish that entered from the “Main” hole). The fish just use different entrances (and passwords to the gatekeeper) to enter the aquarium bowl.
So if you use the guest network without intranet, a printer fish in Aquarium B will be isolated in his own glass partition - he can’t see other fish in the bowl or fish in the other bowl. A “useless” network printer.
You probably knew all this already, but just sharing if helpful for you/others.
Take a leap and try VLAN - I bet the set up isn’t as hard as you might think.