The AP's are not set for multiple SSID, so the employees would connect via one set of AP's and the guests via another.
Ah, ok that was not really clear to me in the opening post from you. Then the Ports need not to
be "tagged" with one SSID only.
Also the pfsense handles the DHCP for both subnets
Yes.