had the same planned here but didn't manage to have it working in a safe and easy wasy.
we have BYOD/Guest wifi and corporate wifi.
Sonos should be reachable by both on a dedicated VLAN....
eventually used a spare Airport Extreme to have a dedicated wifi for the sonos and a controller iPad.
employees can connect to this wifi if they want to control the music.
the Airport is connected to Meraki where it's on a dedicated isolated vlan
It just wasn't worth the time playing with firewall rules and multicast proxies :shrug: it felt like leaving doors open for attackers