Some more design details...
The existing resnet consists of 9 wiring closets which all have home run fibre to the core MDF room. These terminate on an S3500 stack, which does the routing, and also terminates the controller and the firewall. Nice, neat, and self contained. There is a connection between the campus core and the S3500, but it's only used for administrative trafffic and is locked down to specific machines.
The new residence is a partial conversion of an existing off-campu academic building, so the AP's there will have to come through the campus network to the core.
What I'm trying to do is keep the AP traffic off my administrative link by giving them a different IP to point to and an alternate connection from the core to the controller to use.