I had remote last night with a colleague troubleshooting this exact issue. Its always interesting to see how things behave, though people have 100% the right rules, but, order does matter. The gist of it was that customer discovered with the scan people who connect to their wireless guest were able to detect some internal devices, but they just could not connect to any of them, since rule was there to block them from accessing anything related to RFC-1918. But, since rule was there above it to allow dhcp services, that was the reason, so we just move rfc 1918 rule to be the first in that inline layer and then logs showing cpnotenough data disappeared and even doing nc -zv command was also failing, as it should have.
Best,
Andy
"Have a great day and if its not, change it"