Bypass CP for all except Intranet

  • I have the following scenario in mind:

    I have an AP running on a separate Interface on pfsense (with a dedicated subnet via DHCP from pfsense)

    I would like to let guests surfing the net via wireless, but for my people accessing our intranet on another pfsense interface in a different subnet, you need to authenticate.

    I thought I could use the CP for that task but there is only a whitelist, but I guess I would need a blacklist.

    Is there a way to bypass CP for everything but one subnet?

    Or any other ideas?

    Thanks in advance

