In Wifidog.conf there is  a section called "FirewallRuleSet global", if you have the WAN port on your box connected to the rest of your network (so that the wireless users are on a different subnet than your buisness machines) you can change the setting to be as shown, this will prevent your guests from accessing the 192.168.3.x subnet.

# Rule Set: global
# Used for rules to be applied to all other rulesets except locked.
FirewallRuleSet global {
    ## Use the following if you don't want clients to be able to access machines on
    ## the private LAN that gives internet access to wifidog.  Note that this is not
    ## client isolation;  The laptops will still be able to talk to one another, as
    ## well as to any machine bridged to the wifi of the router.
 FirewallRule block to


