Criag,
1. No round robin. The WLC will only flip to the next radius server when the radius server doesn't respond. We have seen issues where the radius server services go down and user auth fails BUT it still responds to the WLC so the WLC doesn't flip to the next one.
2. You can put a load balancer in front for the cert. If you don't, you could get the vaidlate this cert window on some clients like macs and i devices. They will need to validate each cert once before connecting when authing to the radius. They wont be asked again, unless they forget the network and reconnect.
As for roaming. Once a client authenticates the first time a MSK is generated. Its used for seeding material for the PMK key. The PMK key is moved from the radius server to the WLC. This is a session thing. When a client roams from ap to ap or across controller the PMK key is moved with him. This is assuming the client supports OKC.
Hope this helps ..
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
___________________________________________________________