Is the wireless built into the MX or are you using MR APs? If using MR APs to configure/broadcast the SSID setting the configuration to NAT mode using the 10.0.0.0/8 by default will segregate the traffic for the clients and isolate the clients so that they cannot communicate with one another. An additional recommendation to keep it a true guest network is to also modify/ensure that on the Wireless > Firewall settings for the SSID the rule to allow local LAN traffic is set to Deny. If you have to use bridge mode the L2 client isolation feature and block local lan firewall can be used as well but you would need to allow several things such as the gateway ip, DNS server ip if they are local, or anything else that may prevent the client device from reaching internet or resources they should have access to. The MX configuration would differ a bit as you would need to allow specific addresses (gateway, DNS, printers, etc) for things that guests would need access to and then deny everything else so it becomes a bit more involved but still doable.
... View more