Isolate one LAN port for Internet access only

I need to configure one LAN port for Internet access only. I do have Guest WiFi and I would like to do the same on a LAN port. Can anyone direct me to a solution? I know vlan can be a way but I’m not sure how to go about it.
Thank you

Not a bad idea. Actually I would like to have even more multiple OpenVPN types. So some users logged in are only able to access certain services (like nextcloud) and cannot reach e.g. the router admin address at all and other services. While some user could login in an admin OpenVPN reaching everything.

bit late but if you didn’t find it already:

Thanks! I’ll try it out.