Hi,
1) yes, you will have to reserve two IP's for each laptop (one bind with LAN MAC and other with wireless MAC address)
2) you may have more than one IP connectivity (multiple ethernet ports, wireless, dialup etc) to the network but can have only one default gateway. Traffice will flow from the port whichever is connected at last.
3) we are using Fortinet products for web filtering, they have client called forticlient who installs all the policies locally and take updates from the FortiManager. so even if the laptop users are at home or outside office they still have to follow the office policies for surfing the internet. when they came to the office FortiClient send all the data to FortiAnalyzer for preparing the reports.