You can launch the VNS wizard and it will walk you through the process of creating another VNS. You will need a vlan range for your Public ssid, if you don't have it already. Probably bridge at controller is what would fit your needs. Just make sure you egress out the vlan for guest out of the controller network switch ports. After you set up the VNS, go to the topology for Public and setup the dhcp configuration there. Then go to your role for your public auth role and lock it down to allow only the traffic you want. I usually set up guest to allow dhcp, dns to all, block internal ip ranges and allow all for the last rule for the users to just have internet traffic.