As always, there are multiple ways to achieve this. But as you already have a firewall in place, I would go for the following approach:
- Configure an additional WLAN with an additional VLAN on the AP.
- The VLAN terminates on the Firewall where you have the IP-interface and provide DHCP
- The Firewall also controls the traffic from the Guest-VLAN to the other VLANs you have.