Open to suggestions, thoughts or ideas I havent thought of. Thanks.
@Tech9 is right in several respects. Ubiquiti is better hardware and gives you more control. The down side is there is a steeper learning curve vs Asus. Knowing what I now know (that doesn’t hold a candle to Tech9), I would have started with Ubiquiti. Nonetheless, I am happy with my VLAN setup with my RT-AX88U-PRO. It has been running flawlessly for several years with STOCK Asus Firmware (3.0.0.6.102_33421).
My setup includes:
VLAN-1 (router default gateway)
My ‘Trusted’ network is the primary (default) subnet and provides both wired and 5Ghz WiFi to several devices, including port #1 on my DS220+ Synology NAS
Router port #3 is connected to a Netgear GS308T managed switch in the 1st floor office that services trusted wired devices on switch ports 2, 3, 4, & 5.
VLAN-25 is configured on the same Netgear GS308T managed switch in the 1st floor office (switch ports 6, 7, & 8) for untrusted wired devices – isolated from all other LAN but has internet access
VLAN-30 has (6) IP POE cameras, (1) IP speaker and (1) monitoring station connected to a Netgear GS316EP in the attic connected directly by ethernet cable to port #2 on my DS220+ Synology NAS running Surveillance Station in my downstairs office (Note: VLAN-30 is a phantom subnet that is ‘semi-isolated’ from the rest of my LAN [none of the cameras can access the internet and 'call home' on their own]. Normally, the switch is not connected to the router, although it can be for special and temporary maintenance functions. Surveillance Station has access to all subnet 30 devices due to its dual-NIC configuration). By the way, all LAN-30 devices were set with fixed/static IP addresses.
VLAN-20 is assigned to router port #1 and is connected to a Netgear GS308EP in the attic. This VLAN services several 2nd floor untrusted wired devices: TVs and wall outlets. No WiFi on this VLAN. I could connect an AP for better WiFi, but the WiFi I get in the house is sufficient.
VLAN-13 is 2.4Ghz WiFi only for IOT and guest Wifi, This VLAN is isolated from all other LANs but has internet access.
Now,
@Tech9 , before you say anything, I do know that I could have done this with fewer switches

. But the locations of devices and limitations of cabling led be to this as the easiest - not necessarily the most cost effective.
All this to say that from a technical point of view, the Asus AX88U-PRO seems to have the functionality you are looking for. Whether you can make it work for your needs is another story and requires some serious planning and testing.