> their own VLAN) from contacting the internet wherever possible, and entirely block any inter-VLAN traffic other than responses to connections initiated from devices residing on a “trusted clients network”, which hosts my phone, laptop etc.
I am interested in this kind of setup but lack relevant experience. Is this stuff you set up in the stock Unifi admin pages?