What does your security policy requires?
By setting it up in SSID-based firewall, Meraki AP will prevent traffic moving to other network as you desired. Add in bandwidth limitations, there is no way for a guest client to connect to the main network and overload the bandwidth.
Even if you set up a guest VLAN, with client isolation, all guest user will have access to is the Internet.
I work as a security integrator and a number of times I get request for network segmentation and end user thinks that means separate equipment but separate VLAN with firewall rule is sufficient.
Find my post helpful? Please give me a kudo!
CCNP Certified and Meraki Operator