So this firewall block will not block HTTP traffic once someone has authenticated.
config t
firewall cp ipv4 deny 192.168.1.0 255.255.255.0 proto http
We are assuming that your guests are coming from 192.168.1.0/24
And do this to reverse it:
config t
firewall cp
no ipv4 deny 192.168.1.0 255.255.255.0 proto 6 ports 80 80