So why don't you just run a direct connection from a port on the 6509 to the DMZ and dump all the guest users out there? Put the VLAN direct out to the internet and you're done. Its not exactly the same as an anchor controller, but same in principle. The object is to get all your traffic from the guest WLAN's dumped directly in the DMZ so they can't go anywhere else but through the firewall there. You just use a campus VLAN to carry it all to the DMZ.