How can you tell if the APs are tunneled to the controller?
I'm working on this same issue. VLAN 16 is tagged on the AP switchport as well as on the SSID. This was working fine and just stopped. The APs are not forwarding DHCP to the clients. They end up getting a self assigned IP.
DHCP is handed out by the firewall which is connected to the switch in a "router on stick" setup with subinterfaces for each VLAN. Each sub-interface has it's only DHCP server and intrazone traffic is not being blocked.
I assigned a switchport to VLAN 16 and had the client plug in a laptop and he was able to get an IP and Internet access, no problem. So this does not indicate a DHCP issue or DNS issue. It's only when trying to connect on the same VLAN over wireless.
The WLC is setup in an offsite DC connected with a VPN tunnel. As far as I can tell from this setup, the APs are not tunneled back to the WLC. They merely sit on a trunk port with tagged VLANs.