For bridging to work, you can deploy two ways:
- Regular Campus AP with Virtual AP set to bridged (requires that Control Plane Security be on)
- Remote APs with Virtual AP set to bridged (requires that access points at those sites be provisioned as remote APs over your internal LAN)
If you provision those access points as remote APs, you can configure permanent/always/backup SSID that will work if the wan connection breaks and your clients will be able to continue to receive ip addresses from those sites. Radius authentication will not work for new clients if the WAN link goes down.
APs provisioned as regular Campus APs cannot be provisioned with backup/permanent or always SSIDs.
You could also consider running Aruba instant at those sites for survivability.