I just read about configuring source-based routing in user guide (ver. 6.3.1.1-4.0). There is information:
"To allow different forwarding policies for different SSIDs, you can configure source-based routing. The source-based
routing configuration overrides the routing profile configuration and allows any destination or service to be configured
to have direct access to the Internet (bypassing VPN tunnel) based on the ACL rule definition."
Maybe using two SSIDs I could define forwarding policy which will be blocking traffic through backup uplink (for Basic privileges)?