Restrict users on the guest wifi network from using data when a failover occurs

This advice has been very helpful!

For anyone else who may be wanting to set up the same thing, I followed the instructions on the similar case using the link provided, but for the rules I used a source address of 192.168.0.1/24 for the users who are allowed to use the mobile data during failover, and for the guests on the guest network I used a source address of 10.10.10.0/24. This works because connections to the guest network use a different range of IP addresses if you set the guest network up using the guide on the wiki here.

My only issue has been that users on the guest network are still able to access addresses such as 192.168.1.1. The firewall traffic rule does not appear to be working. There is a parameter in the traffic rule settings called “Match” that can be set to “DSCP” or “Mark” and once selected there are “Extra arguments” to enter. Do I need to select one of these parameters so the rule works? If so what “Extra arguments” should be entered? The screenshot in the wiki guide doesn’t show this setting.