You could also accomplish this using static only DHCP entries for the machines on each firewall if you don't have VLAN capable switches.
Yeah.
We did that at the last LAN party i helped organize.
But if you cannot get your guests to register their MAC before the party it's a pain in the ass…
People check in; someone has to go to their place and get their virus-check and their MAC, go back to the checkin, add their MAC to the list at the correct place....
Maybe in the end too much of a hassle.