I understand this scenario but my question is exactly opposite of it. I am seeing any possibility of having VPN on Guest network only and not on main network. Why so? Because this way you can:
1- Any device which wants to use non-VPN connection can use main connection SSID.
2- Any device which wants to use a VPN connection can switch to guest SSID.
I don’t know if on software side this can be implemented but if yes it will be awesome.