I didn't try to decipher the whole post as you rather lost me in the first paragraph.
Modem connects via ethernet cable to the first router WAN as usual. This router would be hosting all your peripheral stuff you want isolated from your main network, but which stuff you want able to access the Internet. As well, the first router will be hosting your second router and /its/ network. From first router LAN port to second router WAN port. Computers, phones, etc. connect to second router and its network. Everything system-wide gets Internet access. Everything on second router can also reach and start a connection to anything on the first router network (i.e. use your phone to view images from a camera, or your laptop to adjust thermostat temperature). Things on the first router network can only communicate with things on the second router network when the second-router-network-thing /starts/ the communication.
This will be the situation with everything set to defaults on both routers, the second of which must be using a different network address range (which it should by default so long as it's the second router configured; connected in this manner).
You'll be able to mess things up from there, but at the start, with both routers newly-set-up it can be expected to act as I've described.