We blocked several ports (udp 161,135-139,445) and icmp traffic; our Hacker's scanner because useless. In addition we filter all traffic from clients directed to the AP (input chain) or other clients. Only traffic from client to gateway (AP is not the gateway, we use bridging) got passed. Maybe not...