Yes.
What you want to do is create a 3 port firewall:
External: Faces the DSL line. Locked down tight, with only ssh/VPN tunnelling allowed. Possibly a well-secured external facing web server, but this isn't advisable either from the security standpoint or the bandwidth standpoint (better to have an external hosting company)
DMZ (De-Militarized Zone): Connected to your wireless AP. Again, locked down tight, and only allows ssh/VPN tunneling in. (Don't trust the wireless encryption).
Internal: Should be obvious