Hi,
You could use below logic.
http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/68097-accesspt.html
You will have to apply the acl on the sub interface rather than on physical interface.
On the ACL for guest vlan you can deny all production network subnets.
I hope that helps.
Regards
Najaf