Are you till facing this issue ?
1st I have noticed that both internet and lan ports are part of vlan 61, please remove the lan port from this vlan at all.
2nd, make sure the default route in the controller is pointing to the ip of the firewall ( if it is the next hop IP address).
3rd, are you using NAT on the internet port or not ? if not then the firewall needs to have a route back to the internal guest network inside the controller, if NAT is enabled then the traffic coming from the GUESTS will be terminated on the controller and then NATed to the internet using the controller's Internet IP.
Think about the Controller's ports as routed ports, what goes from LAN will be routed out of the INTERNET port so proper routing or NATING should be done.