> I don’t want to have a dedicated firewall.
If you want to be assured of protection, you may need to rethink this requirement.
Network 'switches' provide some isolation, but unless you buy data-center level networking equipment, and configure them properly, there is no way to guarantee isolation (i.e., the isolation can be escaped when using a basic consumer grade switch).
My setup to avoid the same issue:
fios <---> Linux router (a PC running Linux) with four ethernet cards installed
first ethernet card connects to fios dmarc box
second ethernet card connects to my internal wired network
third ethernet card connects to an isolated wifi network
fourth ethernet card connects to cisco hardware VPN box (work provided), work laptop connects to this hardware VPN box
Linux firewall rules setup so that the work laptop and cicso VPN box connected to the fourth ethernet card has no access to any data on second or third ethernet cards and no knowledge even of the existence of those additional ethernet cards.
Work laptop does not run over wifi, ever.
This layout has the work laptop on a fully isolated, wired, network, where I have full control over what it can see (via those Linux firewall rules).