Noob question: Why do my separate networks see each other when they should not?

  So I have a WAN, LAN, and WLAN.  Clients from my LAN see clients on my WLAN, and vice-versa.  This is bad.  Is it because automatic outbound NAT rule generation is enabled by default?  Is that what bridges the two networks?

  what do you mean by "they see each other". how do you test this?
    AoN doesn't bridge anything.
    it defines how traffic is NATed on the various interfaces.
    --> if there are no AoN rules you have a purely routed setup.
    rules to define from where to where one can communicate are on the firewall rules page.

  Your firewall rules are probably allowing it.

  If you have rules allow any any, then they will see each other.

