I don't have the Disney Circle on hand yet to test but here are some of the thoughts I had: Is there a way to have the MX DHCP assign the Disney Circle IP as the default gateway to avoid the need for spoofing/poisoning? Is there a setting on the MX that internally blocks ARP Spoofing/Poisoning?
Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO If this was helpful click the Kudo button below If my reply solved your issue, please mark it as a solution.
What I did was plug it directly to a switch port, set the VLAN on that switch port to the same VLAN as the wireless devices, and walked off. It worked as intended, without affecting the rest of the network.
We no longer use it for two reasons: Group policies in the MX and Apple's Screentime implementation in iOS 12. The latter made the Circle irrelevant in our setup.