If I'm understanding the translation I got correctly you want your wireless clients to be able to talk to your AD servers without routing through the MX. You would need to set your SSIDs to drop traffic onto the same VLAN as the AD server or if you had a layer 3 switch available you could move the relevant routing there. Do you have a specific goal in mind? Like lowering the load on the MX or ? If everything is working right now without performance issues, I'm not sure I'd be making any changes in the same circumstances, but I may be missing something with the translation.
... View more