The boss has decided that we should have a second wireless access point for guests, that can see the internet but not the LAN. Seems reasonable (I thought) and I figured I'd put the access point into one of the RV082 ports, use Port Management to assign that port to VLAN2 and then set up an access rule to deny anything with a source of VLAN2 and a destination of VLAN1. That said, I couldn't find an option for the VLANs as either a source or destination for an access rule. So I guess my real question is, can I do this? Or have I misunderstood what VLANs are for? Also, how would DHCP be handled in this case? In our normal LAN, we have a DHCP server so we are not using the router for this. J.