For guests I prefer to use a separate client vlan that is extended to the firewall. To prevent guests from accessing my corperate dhcp server, I prefer to use dhcp on the firewall to completely separate it and still maintain a central point of control.
But offcourse there are more possibilities such as use internal vlan with snat, rather than my external vlan example.
Please read the Aruba-Instant-Validated-Reference-Design, the dhcp options are well described, link.