If the locations have an MX they can do a VPN tunnel back to your core where the Radius server lives. Then you can give the APs static LAN IPs to use to add to RADIUS. Should be more secure to keep all that sensitive traffic in a tunnel vs traversing the internet.
Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.