You can use the ESI module for policy routing. In the below example it would route subnet 10.10.x.x out the 172.16.99.7 default gateway, all other traffic would go out the controller's default gateway. You make the trusted and untrusted ip address the same in a policy route.
Jenga
####
!
netdestination student-networks
network 10.10.0.0 255.255.0.0
!
esi ping health-30sec
frequency 30
timeout 1
retry-count 2
!
esi server student-gateway-1
mode route
trusted-ip-addr 172.16.99.7
untrusted-ip-addr 172.16.99.7
!
esi group student-gateway-group
ping health-30sec
server student-gateway-1
!
ip access-list session "redirect-students"
alias student-networks any any redirect esi-group "student-gateway-group" direction forward
!
user-role student
session-acl logon-control
session-acl redirect-students
!