About the secure tunnel option, when the controller is deployed behind NAT this is not supported at this moment.
known issues:
o Availability pair, if two Controller behind NAT can’t be identified
o Image upgrade fails if Controller behind NAT
When...