First off, why do you need 2 routers in an apartment? How far is the AP from the Router? Because I have a 3-bedroom good size apartment and a single RT-AC86U covers every single room, including the furthest bathroom through 3 walls 15 meters away in a straight line. It's not necessary to see full 5-bars signal strength in every single corner and it's not necessary to shoot your WiFi to all the neighbors around you. Too many radio devices close to each other only increase interference and do more harm than good. Also, if you have a Router or AP close to your bedrooms, better remove it or move it away.
This what I would do in your case with one router only:
- put the ISP router in Bridge Mode, use it as a modem only
- make RT-AC86U my Main Router, move it to a central location, preferably
- run OpenVPN Client on it as network-wide VPN (local server and fast public DNS for maximum speed)
- assign static IP to all my devices in LAN -> DHCP Server
- select which device will use WAN and which VPN in OpenVPN Client -> Policy Rules
- SSID1 2.4GHz for all older devices, fixed channel, 20MHz wide
- SSID2 5GHz for all newer devices, fixed channel, 80MHz wide
- Guest SSID1 2.4GHz (for compatibility, for actual guests), no access to LAN, no access to each other
- route this Guest SSID1 through WAN and set Adult Content / Malware Filtering DNS (
YazFi script)
- Guest SSID2 2.4GHz or 5GHz (depending on what I want to connect there), access to LAN and between each other
- route this Guest SSID2 through WAN, default DNS or anything else I may want (
YazFi script)
This way I get:
- less channel pollution and interference, possibly better sleep due to lower radiation levels
- all devices not in DHCP list go through VPN by default, if connected to SSID1 and SSID2
- all devices with Static IP addresses go through WAN or VPN according to my preference
- all guests use Guest SSID1 through WAN and with Parental Control, guests' kids may connect too
- if I want to go temporary through WAN on a device selected to go through VPN -> connect to Guest SSID2
What is needed:
- RT-AC86U router
- Asuswrt-Merlin firmware
- YazFi script
- AcrylicWiFi software (free, or similar) to find the right channels for my WiFi
- read RMerlin instructions for Policy Rules and Jack Yaz instructions for YazFi script
Setup time -> about 1h
Extra expenses -> none
Issues with wife -> none
Level of happiness of family members -> high
What else do you need?

Do you want to sleep on the couch for a very VERY long time with all your VLANs, APs, Cables and Switches? Keep it simple and enjoy the life. I understand RT-AC68U is your old router and you really REALLY want to put that thing to work, but it may not be needed.