Couple of questions for clarity:
- What device is conencted to the "internet" interface?
- What is the default route for users?
- Are you source nat'ing the guest wihtin policy or the VLAN; or should they route directly out the "internet" interface
If you are source nat'ing clients, you need to ensure the controller's default route is out the "internet" side, not the LAN side. You'll then need to add static routes to any internal networks necessary.
If you are using a device on the "internet" side to be the default gateway for the clients, then you'll need to make sure you are not source nat'ing anything.