@ww and @jdsilva are correct. Create a seperate VLAN for the guest traffic. Bridge the SSID to this new VLAN (using VLAN tagging). Then connect a security device, like a Cisco Meraki MX to that VLAN, and out to the separate Internet circuit.
... View more