I have a 2860 and four AP903s. Unfortunately the APs are on the inside of the firewall, and the 2860 is of course on the outside. The APs reguster via broadcasts, and of course the 2860 is on a different subnet. I'm sure there is a way, but...
The only problems I've had with the 2860 were faulty IPv6 support, and more seriously the internal firewall (which I turned off) was still blocking zone transfers from my primary DNS (which is on my network). But they fixed it within a week once I worked out what was going wrong.