I would suggest moving the VOIP vlan and the new ISP into a second virtual router. then they will be completely isolated from the current setup. By default everything is in the trust-vr. And there is also an untrust-vr already existing.
Create two new zone and assign them to the untrust-vr
assign the new ISP interface and the VOIP interface to these new zones
create the necssary policies to permit and nat the internet traffic for the new zones.