The Access Point does indeed eliminate the need for specific pairing. Its a little bit of a pain in the azkhaban to set up so if you do choose that path I would look at good ol' Carl's supplementary documentation here: VMware Access Point | Carl Stalhood
However there is no way to only have RSA affect the incoming traffic from the access point (feature request) so if you are using RSA and you don't want your internal users to have to use a token you still need a second connection server.
Josh