Hi,
Don't you want to have WLAN bridged locally instead of tunneled to VX, what is officialy a no-go? Or is it tunneled to another endpoint device?
If your traffic is tunneled, the switch the controller/gateway is plugged into has to comply with the VLAN settings. Hypervisor virtual switch VLAN settings, and the DC switch underneath.
If you go for bridging mode local then it will make sense to test Internet connection from VLAN 16 on the AP-plugged switch.
Isn't that something you might want to adjust?
Hope that helps,
Tomasz
Edit: I see you wrote clients are getting IP address though, sorry for maybe introducing some confusion.