Disclaimer: I'm not a networking guy, but I've worked with them.
If you're looking for security, you set up vlans. I don't know enough about your setup to know if you setup a vlan, or just a separate subnet.
The goal is to have separate vlans, to block all traffic between the two networks, and then add exceptions in the ACL. The ACL is essentially a firewall between the two vlans.
With this in place the smart device can't scan your network to gather info. Also, if it gets infected, it can only attack through the opened routes or the other devices on the vlan.