Try the following under the user-role and see if this helps :
Create an Alias
(controller) (config) #netdestination LOCAL-SEGMENT
(controller) (config-dest) # network 192.168.0.0 255.255.0.0
Create an ACL allowing this traffic
(controller)#ip access-list session ALLOW-LOCAL-SEGMENT
(controller) (config-sess-ALLOW-LOCAL-SEGMENT)#any alias LOCAL-SEGMENT any permit
And turn on under the System profile of the RAP AP-Group
If this doesn't work you may have to do by IP or open a TAC case to see if there's anything else you might need to do.