I think you should engage a Cisco partner. It is clear you have a network with a lot of complexity. Are you able to put the AP's at each branch into a single VRF that goes back to your DC's, and default route that via a central MX and out to the Internet? If so, then yes.
... View more