Hi Colin,
On my Guest SSID, I have set the Access Type as Network-based, and allow access to DHCP, DNS, HTTP, HTTPS and UDP 4500.
Doing a show datapath as you suggested, I do not see any UDP 4500 on the controller.
I have attached a .txt file, showing the output from show datapath.
xxx.xxx is the originator, and yyy.yyy is the receiver