The only way it will work in route mode is if your VPN pool that you put clients into is on a subnet that is currently on the controller. If your controller has a VLAN that has an ip address like:
192.168.1.1 /24 , you would need to have your VPN pool like this 192.168.1.10 - 192.168.1.50.
When you do that, the clients get a fully routable address that can be reached by your infrastructure, without requiring nat