Just don't NAT at the router. Create a second subnet and assign it to a different interface on your router (if you have one available) then connect that new interface to your wireless network and use an ACL to keep the networks separate.
Or you could use private VLANs; but I don't know what kind of hardware you are running or if it supports them.