This is the major link I used as my reference for setting up multiple vlans, the link starts with vlanctl command
later switches to linux ip command. The ip command did not work in my situation I have another dual WAN complexity that didn't play well with ip.
I also had some strange issues, it seems when I started creating vlan's below 100, they didn't have internet access. Maybe I overlooked something.
All, While the search revealed several hits on the vlanctl and ethctl commands used in the new Broadcom chips, as in the RT-86U, there is not yet a definitive guide or howto on to properly use them to control the VLANs on these routers. Obviously in contrast to the more we’ll known robocfg...
www.snbforums.com
This is another Link I used to put together a VLAN that connects my LAN devices connected to managed switch assigned to a VLAN that
gets bundled together to the same vlan as guest wifi.
It took me a while to make this thing work. I could find some configs but nothing worked as provided. After combining information from several different posts I came to the working solution posted below. As it took me a while to get it to work I figured I'd share it here in case anyone else...
www.snbforums.com
You still have to use some iptables that was listed in the 1st link, 1st link also showed with the vlanctl how to create a vlan interface even for the
Native Vlan 1 that actually has no tag.
There are some strange quirks still I haven't figured out, it seems when I reboot my router, some of the WIFI IOT devices somehow are getting the IP assigned from the main network, not the subnet designated to the bridge interface that the guest wifi is part of. If i restart the IOT devices they than pick up the correct ip address from their respective vlan subnet.