Proxy-RADIUS means that the NAC gateway will not be in any domain and RADIUS is domain independent. You would set up a RADIUS server such as Microsoft NPS in each domain, and then NAC would parse the RADIUS requests and then forward the request to the appropriate domain. This allows the requests to be answered separately by each domain and no trust is necessary. Since DHCP is also independent of domain, you just need to add NAC as an ip-helper, bootprelay, or as an additional DHCP server in your network configuration.