Hello,
The best option, if the WiFi devices do not need to communicate with each other, is to in the Advanced WiFi interface config, enable the Isolate clients option.
Also, in the firewal, set up a rule, thank would block traffic from Subnets of WiFi interface to destination device input and select the 80 443 22 ports. Other ports will be needed for DHCP NTP and what not