FAQ: RAP mesh needs to be placed on a different network from controller.
It is recommended to place remote mesh portal on different vlan which does not exist on the controller.
RAP does not recognize trusted/un-trusted network. It always opens an IPSEC tunnel to controller whether it is coming over trusted network or un-trusted network. If a RAP and controller with split-tunnel config are in same L2 network, RAP can reach controller via its br0 (uplink e0) interface and also through gre0 (gre tunnel) interface. Gre is L2 interface. Hence, controller’s bridge entry will keep bouncing between br0 and gre0 interface on RAP’s datapath, resulting in RAP being unstable (Rebootstraping).
For configuring remote mesh portal and point, refer kb article ID: 1052