I set up the same masquerade for the 10.0.0.0/24 network on my MT box with two interfaces. The masq would only work for one interface at a time.
Is this a bug? Version 2.8.17.
Okay, that is the first part of what I was looking for!it is far more simple!! in wireless ap setting set `default-forwarding=no` and the clients will not be able to talk to eachother