Not the best solution, but since I inherently trust everything that's hardwired with an ethernet (or at least limit via permissions its access to shares) and inherently distrust everything that's WiFi, all the WiFi devices on my network only connect to the guest network which has no access to anything else.
Only MY phone and MY tablet connect to the real network. My wife, my kids, my doorbells, TV, my dog's collar (I think this annoys the pooches to no end) and most especially my freeloading sister in law who's living with us "temporarily" etc etc etc all connect to the guest.
For hardwired connections that I don't trust I keep a separate router to isolate it's network completely (simply because I don't have a managed switch)