Okay, clients will always appear in the user table of a controller when any traffic is seen by them on the untrusted interface. Here is what we need to do:
We need to change the ip cp-redirect address on both controllers to the ip address of the VRRP. We can only do this on the commandline:
Type "show ip cp-redirect-adress" on the commandline of both the master and the backup master. They should both point to interfaces that are local to each controller. That parameter determines what ip address clients that use captive portal should be redirected to. I am guessing that the standby or backup controller is answering with it's own local address. Change this address on both controllers, via the commandline:
config t
ip cp-redirect-address <ip address of vrrp>
See if that helps.