Jack - Welcome to Aruba!
I assume this is our Instant AP line?
All of our WLAN includes a stateful firewall. Please consider using it. On your Instant APs, when you setup the guest SSID, there should be an option for access policies. I would select network based and then create the following rules
permit DHCP
permit DNS (can specify specific DNS servers here as well)
permit ICMP
Deny to "internal subnets" (usually this is 192.168.0.0/16, 10.0.0.0/8, and 172.20.0.0/20)
permit any any
Using the above, you are only permitting the guest users to the public internet. Putting an ACL on the VLAN is another option but it's more involved and not stateful.