Preventing Wifi clients to access WAN from specific zone

You can, but you defined 2 networks that overlap as a result of the /16. Smaller networks (/24) make it easier to avoid overlap. There are rarely reasons to use networks larger than /24 - only necessary if you have more than 254 hosts. And if you do have that many hosts, you need to be very deliberate about how the networks are configured - large networks become inefficient.

The problem was not the size of the network, it was just that you had 2 of them and they conflicted.

If your problem is solved, please consider marking this topic as [Solved]. See How to mark a topic as [Solved] for a short how-to.