You could create a vlan for management only and a vlan for portal users, if your hardware supports it... Works well with my DLink AP.
Or another method could be simply set the access point ip to a addres not in the subnet, but this would kill your ability to manage the ap...
|