As Tyler said, you can tunnel traffic (user and control based on your configuration) between AP and controller over IPSec UPD traversing NAT points in-between today. Anything else, please follow up with PLM team directly.
We already use RSSI as one of the parameter to stir client to "right" AP today. This is just another Cisco complexity left for customer to figureout... how would customer figure out a specific RSSI level that would prevent sticky client? This is not ...
Wireless controller can be manager via IPv6. However, AP and AP-WirelessController communication need IPv4.
On dataplane side, we support clients using IPv6 in B@AP topology. In addition, you can configure the policy so that you can separate IPv4 and...