Enabling wireless client isolation on APs should help with a flat bridged wlan.
But this august school start has been a terrible nightmare, even with captive portal disabled, the connection through pfsense is extreamly slow, nearly unusable.
The OP didn't clarify if performance is equally bad for users connected via wired?