So here are my results from testing using Wireshark
Scenario 1:
Guest network is placed in VLAN 100
ip cp-redirect-address 192.168.100.17
Client attempts to visit google.com
Client gets temporary redirect from spoofed IP address of google.com via the Aruba
Client does DNS lookup for redirect, and successfully connects to the captive portal page
Scenario 2:
Guest network is placed in VLAN 100
ip cp-redirect-address 10.10.25.17
Client attempts to visit google.com
Client gets temporary redirect from spoofed IP address of google.com via the Aruba
Client does DNS lookup for redirect, and received the spoofed DNS reply pointing to 10.10.25.17
Client attempts to connect to 10.10.25.17
In wireshark I see tons of "TCP ACKed unseen segment" errors
Client is unable to connect to captive portal
Scenario 3:
Guest network is placed in VLAN 25
ip cp-redirect-address 192.168.100.17
Client attempts to visit google.com
Client receives no response at all and times out
Scneario 4:
Guest network is placed in VLAN 25
ip cp-redirect-address 10.10.25.17
Client attempts to visit google.com
Client receives no response at all and times out