Okay, Started may OpenWRT project to change and lock down my home network much much more. It took 6 days to get were I wanted with testing and implementing a portion of it. What I am going fore is my main router (which will soon have openwrt on it soon) to stay as the main router for now. I set up the openwrt one router to have the 2.4ghz channel on the 192.168.20.0/24 network for guest and iot devices. They can see each other and the internet. BUT they have no access to items on the 5ghz channel nor any on the main router. This now works and I've tested it with nmap on all ports. The iot/guest net is totally locked down as I wanted. I have a third router which I plan on doing something the same as my new openwrt one router. But will be upstairs for outside iot devices and cameras (open source ones that are trusted).
Well, I first started out using LUCI (the web interface) and quickly went to UCI commands from the terminal that I can directly tie into on the usbc port of the router (you can't get locked out of that one that I could see). Then I went straight to the /etc/config/ and just would edit those files directly.