So the default route applies to the entire appliance. You will either
have to attempt using some policy routes which I've found to only be
semi-reliable or create a VDOM for your guest network. This creates a
virtual "second" appliance that runs on t...