Do you need captive portal for this ssid? If not, you can use the the IAP-VPN configuration. The IAP must be whitelisted on the controller and the controller must be running 6.2 or above. In the 6.3 user guide, this config is detailed in Chapter 41. The instant user guide includes details on that end how to set it up.
There are multiple VPN modes you can run in. Please read the docs (or enlist a partner/Aruba SE help) to pick the best one. The "hooks" if you will in this design are specified in the VPN section on the IAP. First, you select the controller VPN termination points and then the routes into corp. If you want to tunnel ALL traffic put a 0.0.0.0/0 route in this table:
2. Then you select DHCP server and select the mode and addressing you wish to have (L3/local modes) The VLAN ID you select here is CRUCIAL
3. In your SSID settings, the VLAN from step #2 above is mirrored here. That is the "hook" between the WLAN config and the VPN config and how the IAPs know to place clients into a VPN configuration.