Limiting scope and 3rd party access to the CDE.

I am currently trying to limit the scope either by creating a vLAN I have no idea how, or using a firewall, however the router is used for other functions besides the epos how can I best securely and reliably isolate the CDE.

Also I how do I secure my CDE which uses TeamViewer for 3rd party support access. Surely that’s a vulnerability issue? Is there a known solution?

I’m just running a couple of takeaway stores with an entry level epos I don’t understand how this is all so tech heavy and complex surely all stores can’t be doing this with the apparent expertise or tech professionals needed to be compliant am I missing something?