Hotspot on a 411 that is bridged

Hello,
We currently have a 411AR unit that we have setup as a bridge between eth1 and wlan1 just to provide wireless in our office. (IP range 192.168.10.x)

What we would like to do is setup a virtual AP so we can have hotspot on it also for guest. (IP range 10.1.10.X)

The problem I am having is getting some rules in place so that someone on the hotspot network cannot get to the IPs in the office network. If it were our main router, I know how to add a rule to have it drop when they try to access 192.168.10.x. Is there a way in our 411 unit to only let them get to the firewall (192.168.10.1) and nothing else in that range?

Thanks