Device Isolation in AP Mode
The additional IoT network and the Device Isolation feature in the current firmware seem to be working well when the router is in Wireless Router mode. However in AP mode, the Device Isolation feature is not available. Testing shows that when using an additional router in AP mode, the IoT devices are not isolated even though they are listed in the Device Isolation list of the main router. Please consider adding the Device Isolation feature to the AP mode settings.
The workaround for now is to put the secondary router in the Wireless Router mode, operating independently of the main router, with both routers connected to the ISP router. This of course means double NAT, which for me is not a problem so far. Both routers use the same SSIDs but operate on different channels.