hy,
i had a setup like this that was working, but there were small differences.
non authenticated network was routed vns - next hop routing
authenticated network was B@AP tagged
i had a seperat vlan so that "guest" traffic was not on my LAN
in the non authenticated profile you have to work with policies!
the setup made problems because the client has to change ip when switching from not-auth to auth network. some clients (ios sometimes also android) make problem with such setup