I managed to set up my wireless router with security I wanted. I can not drop any encryption, - now it's still WPA2, but not needed any more. It uses OpenVPN. OpenVPN can "push redirect-gateway". And then all wireless clients get 1 IP in the  network where they can see only router, and on it - only udp port 1194 is open for them. No through traffic. It's sufficient to establish openVPN connection. And get access to internet and LAN resources in this OpenVPN protected LAN.