usually for that purpose I create 2 vlans in 2 SSIDs i.e.
1. create 2 vlans
SWITCH
STAFF vlan10
GUEST vlan20
2. create 2 ssids
AP
STAFFSSID vlan10
GUESTSSID vlan20
connect ge0 AP to trunk port on the switch
3. create acl in switch
-allow vlan10 to servervlan and internet
-allow vlan20 to internet only
NOTE:
I never tried myself in Huawei but I ever tried in Cisco