I recommend the suggestions from Doug and Ron. The queries above are network level decisions and are not just controller configs. I would suggest make these design decisions with help of Partner.
For the above question : Assuming that VNS NonAuth topology traffic is B@AP, DHCP Server is in DMZ VLAN, Clients placed in Wireless VLAN, you can configure bootprelay in Extreme switches. Follow below link for more info :
https://community.extremenetworks.com/extreme/topics/new_to_extreme_need_help_with_configuration
Since you are planning for B@AP you need to tag client VLANs in EWC, but needed to switchport connected to AP. In controller you need to configure B@AP topologies that will be pushed to APs.