Here is just an idea. There is a few ways of doing it.
I did it this way to give you a better idea of how subnetting works. However, if I was doing it personally. I'd only have one switch and do VLANing but that get more messy to explain so someone that doesn't do VLANing often.
Depending on your projects requirements. Subnets would be completely isolated. If users needed to access the other subnet to get to web server etc... they would have to go out from the WAN and back in to access it. Just like everyone else offsite.
If you are doing it via VLANing or firewall policies. You could allow exceptions through the firewall to allow internal devices to speak to the external ones over the LAN directly. But I suspect this would go against your project as the point of this is to keep the two separate. (security reasons).