I'm trying to figure out almost literally the exact same scenario.
I'm still looking for the start of the learning path to help me solve that one, too.
I'm thinking some kind of bridge between a single device on a sandboxed guest wifi connection and a single device on the protected LAN side, to...