This is pretty much a standard configuration. You can safely enable this by Firewall: Rules: LANSource LAN Net; Destination Any ; Action AllowFirewall: Rules: GUEST_LANSource GUEST_LAN net; Destination !LAN Net: Action Allow
Enable logging for certain rules and see if an earlier rule applies or if those rules apply at all.