Have yuu tried Rsurana solution?
# set security zones security-zone internal interfaces irb.10 host-inbound-traffic system-services dhcp # set security zones security-zone guest interfaces irb.20 host-inbound-traffic system-services dhcp
On trust zone you have allowed all system-services and all protocols. That will also do but for obvious reasons is not the best implementation.