There are really only 2 ways to segregate the traffic and both are reliant on your router supporting the functionality....
1. VLANs. You would want to create a new "unsecure" VLAN for your sons PC (and possibly the Wifi!) and then add a bridge to route traffic between the VLANs virtual interface and the WAN interface.
2. Separate subnets. Different IP ranges for different machines and then a route to allow the new subnet to talk out onto the internet. A clever user could reconfigure the network connection to bypass this though.
I do number 1 on a DD-
WRT router but unsure if the Asus supports it.....you may need a new router.