Ok. Here it is in detail:
First - you need to setup that broadband connection on a separate physical interface on the controller so that you can place guest users on it. We will need to setup a VLAN specifically for this network and tie it to that specific physical interface. The controller will also need to have an ip address on that interface and we need to indicate to the controller, that is the ip address we want to serve the captive portal on. The ip address of the controller must be in the range that the broadband router is giving out.
config t
vlan 1000 <--------- Set up guest vlan
interface vlan 1000
ip address 192.168.1.250 255.255.255.0 <------- Ip address on that guest Vlan
exit
ip cp-redirect address 192.168.1.250 <--------- Indicate to the controller that is the ip address you want to host the captive portal on
interface gigabitethernet 0/3 <-------- Choose the physical interface on the controller that you will be plugging the broadband router into
switchport access vlan 1000 <------- Assign that Vlan to that port
Next, if you already have a radius server configured to authenticate users from Active Directory and it is working, we need to configure a remote access policy on that radius server that (1) allows PAP and a Nas Port Type of VPN:
Do you have Windows 2008 or Windows 2003 for your radius server?