My boss and I were contemplating having the wireless users attach to wireless, but then those accounts would have to be authenticated to an NT box with a domain account. The NT box would then be routed to the appropriate network. The DMZ port idea doesn't sound all that bad, but I would still be leary putting an access point on a DMZ. It might be entered via telnet much easier from outside than it would behind the DMZ. Or even DOS'd from outside the DMZ, depending on the firewall and ruleset used.