DMZ Anchor.
ip address 172.16.1.0/23. Plenty of space for the client.
Local
ip address 192.168.1.0/24. No layer 2 VLAN associated, or you can create one and at L3 ip route 192.168.1.0/24 null 0, to stop them from getting anywhere incase the anchor breaks.
Client associates, to the local, is pushed across the mobiltiy tunnel to the DMZ, where they get IP 172.16.1.50/24. As this is where the IP subnet resides, what ever routing and FW policies you allow are followed.
No Anchor:
Local WLC
Ip address 192.168.1.0/24. Client gets an address in this IP subnet, and foloows the local routing rules you have defined for the subnet.
Steve
HTH,
Steve
------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered