To protect a wireless network in an enterprise environment, you can use Radius + VPN on top of, isolate the AP from the rest of the network (plug it into the radius server) and this should provide a very good level of security. You should probably enforce LONG, complex passPHRASES and p2tp VPN (which includes IPSec! yay).
Downside : its -kinda- annoying to setup, and if you don't do it right, nothing will work (on the wireless side that is)
