You would need to configure a second SSID linked to a different VLAN. Then at L3 create ACL that denies the "guest" from
reaching to the "internal" networks.
HTH,
Steve
------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered