Hotspot configuration

Im trying to host a hotspot setup where the local subnets are not interface subnets
of the tiki box. i.e subnet–>L3 switch–>uplink vlan–>tikibox LAN int—>tikibox WAN int (HOTSPOT).
My testing isn’t proving to be possible and the only way I see this working is if the L3 switch/router
nats the subnets to a range of the tiki box interface subnet.
Comments? - many thanks in advance

Hotspots heavily rely on being the layer 3 hop. If you NAT an entire subnet everyone in that subnet will be able to pass traffic if one person logs in.

Agree if your doing nat one-to-one. Its a clunky idea however, so looks like no way around. thanks