The DMZ is another port on the firewall but specifically to make for easier access from outside of it. Hence web servers and e-mail server access. Doesn't make sense to put a access point on it, unless you can filter ports going in both ways to your trusted and outside networks. But then you'd have to be using something like Cisco PIX or Nokia firewalls. But putting such a device there can make the temptation of getting into it that much greater, and potentially easier to hack from the outside without having to know the SID or WEP keys. Simply telnet into it and change the keys from outside the network unless your firewall blocks port 23. All our webservers, VPN's and e-mail servers reside in the DMZ here. But we use Nokia firewalls to block traffic both ways in/out of it.