Full client isolation in pre-9.7 blocked on L3 (IPs, not MACs). Enabling it without a whitelist allowed certain traffic through, but wasn't enough for a captive portal. Ruckus support couldn't tell me which ports were allowed.
9.7's full client isolation works a lot better, and forces you to define a whitelist.
Also, a note about local- it's per RADIO, not per AP. I'm not sure if it has been fixed recently, but in 9.7 and earlier it will only isolate you from the clients on the radio itself. If you are connected to the 2.4, you can see all clients on the 5, and vice-versa.
For this reason alone we have been moving to full client isolation.