1. it is true, all Radius requests were sent by the virtual controller address
2. it is a question of the configuration overhead (AP and Radius Server) and the functional safety with regard to bugs or something
I would use the Radius Proxy to avoid configuration mistakes and a single point of configuration