I don't know about attempting it all on one router, but maybe this thread would do what you want with a second wireless access point plugged into port 4. Remember an Access Point gets the access permissions of the port it is plugged into. So all Wifi SSIDs on the access point will be on the new private network
Note robocfg is configuring hardware ports, so you should use the command "robocfg show" to confirm that your hardware is connected in the same way as the post. Plugging a device into port 4 and unplugging it, should show a change in the output of the robocfg show command.
The iptables rules containing br0 are about blocking access to/from the router's network, but later in the thread they modify rules to allow access to a nas device.