Dear Juan Manuel,
Thank you for reaching the Small Business Support Community.
You have already added the four Virtual Access Points (SSID's), all with their unique VLAN ID's, so the traffic to the Layer3 device carries a tag with their corresponding VLAN ID where, if allowed by the Layer 3 device, you can configure an access rule or policy to permit or deny the traffic to/from a specific host or network segment. In other words, the restrictions must be configured on the router or layer 3 switch this AP is using as a gateway.
Channel Isolation appears to be an option but that just blocks the communication of devices within the same VAP (Virtual Access Point).
You may contact, if entitled to, the Small Business Support center for further assistance;
https://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html
I hope this helps and please do not hesitate to reach me back if there is any further assistance I may help you with.
Kind regards,
Jeffrey Rodriguez S. .:|:.:|:.
Cisco Customer Support Engineer
*Please rate the Post so other will know when an answer has been found.
Jeffrey Rodriguez S. .:|:.:|:.
Cisco Customer Support Engineer
*Please rate the Post so other will know when an answer has been found.