I've discovered what I think is a bug, but I want to see if anyone else has made this work. I do have a support case open.
I've found that if I enable WPA2 RADIUS authentication on an SSID that is tunneled to a MX64W security appliance, that the Access Point doesn't actually send any RADIUS packets on authentication. In fact I sniffed the traffic at my NPS server, and I don't see *any* port 1812 traffic, from either the security appliance or AP. Has anyone else seen this?
I will say that the VLAN that the traffic is concentrated on in the security appliance is a VLAN that doesn't exist anywhere else on the network, it's just in the appliance for L3 roaming. Internet access works perfectly through the security appliance if I don't try to use RADIUS auth.