On my Mikrotik router I put guests and unknown tech on a virtual WIFI network bridged to an isolated VLAN (extra enforcement with firewall rules), I only have necessary management ports open on the main VLAN (no DNS caching on the router to reduce attack surface) and no port open from WAN/guest VLAN. For WIFI security I use WPA2 AES Only, no PMKID and no WPS. I prefer to just block ICMP redirect request opossed to blocking the entire protocol on the input chain, blocking ICMP completely can break things and decrease performance.