  is there a supported design where all guest traffic can go to a centralized " controller" in the data center then from there they can get to the internet? I'm trying to have all of my guest users use one NAT IP address only from all remote sites. the current design is all guests are using the same IP address that the site uses to access the internet. 


Depending on your network design, you could look at layer 3 roaming with a concentrator, or vpn tunnelling with a concentrator.


This will tunnel all traffic from the SSID to a specific MX.

Thank you !  I will do some testing 

