Yes, you should be able to tunnel your Guest Network WLAN back to the SZ controller, and VLAN it off to either ISP, versus local break out (LBO) and drop client traffic for the corp net at the AP switchports.
The SZ-100 has built in Dataplane, so just configure Tunneling under your Guest Access WLAN advanced options. We use RGE by default, no 3rd party equip required.