So WINGATE will provide the security I need so guest wont access my domain folders etc.
It sure can. You will want to put another network adaptor in the WinGate computer to serve the wireless network. This will keep your wireless network physically seperate from your main network, while still allowing you to serve internet to both networks from WinGate.
There is an option in WinGate's ENS that you can disable to stop seperate networks being able to reach each other by routing through WinGate. If you are using WinGate VPN, you won't be able to disable this option.
- Gatekeeper -> System tab -> Extended Networking
- Uncheck "support for multiple subnetworks (router)"