We ran into this as well, still on 17.10, but, I was able to at least work around this issue for a small branch office.
Create a policy group for IOS devices
Create a L3 Firewall rule to allow 17.0.0.0/8 (apples subnet)
Create a traffic shaping rule for subnet 17.248.190.0/24 (17.0.0.0/8 would also likely work) and set the DSCP tag to 46 (EF - Expedited forwarding)
Tell IOS users to turn off "Private wi-fi addresses for the wifi network connected to" https://support.apple.com/en-us/HT211227
Move IOS users into correct policy group
Again, workaround for a small office, so does not scale too well, this was done on a MX64W