I just thought about something. What about wired devices, can those be force to the separate subnet?
not on the regular asus routers no, only wifi.
I have my echo, blink, and ring devices on an isolated guest network. smart lights and smart plugs on another. They all communicate through the internet so its no problem accessing them through my phone. But My smart TV's and printers I have on my main network where I have my mobiles and desktop pcs because i like to use chromecast with them and be able to print through network. I have samsung camera devices on another guest network where I temporarily allow intranet access which is necessary to change settings through my phone, but then I put intranet back to disabled which is good enough to see live video and get motion alerts from them. I also have a thermostat alone on a separate guest network to keep it isolated from the rest. So it all depends on your devices you will have to test them to see if they work or if they need access to main network or not.
Guest 1 seems to be more isolated then the rest so if you have issues might want to try guest 2 and 3 which is what I did with my fire stick and echo home theatre setup or might have to put a setup like that on the main network.
IMO< there is no point in setting up a guest network with permanent intranet access. You might as well just use the main network. Only other reason I can see is if you want to group alot devices together to easily limit bandwidth maybe or have it on a specific schedule and timelimit.
But I gotta say it all seems pointless for security purposes because all it takes is one compromised device. Once I start putting smart tv's, printers and a copule smart devices on the main network it kind of defeats the purpose. At this point it feels like something I'm doing as a tech experiment rather then for any real practical purpose. But I guess something is better then nothing.