1. In that scenario it is recommended that the master can communciate with the RAPs (for ARM and RF data) . To do so, the master needs to be able to route to the L2TP pool. The easiest approach is to make this a routable network (with the last hop being the local controller). If you cannot, and the master is on one of the same networks as the local, you can add a static route for the L2TP pool to the local.
2. If you are converting an IAP to controller-based RAP, you can point the IAP at any available controller (so long as it is whitelisted), it does not have to the master, it can be your local that is already accessible. It would then function like any other RAP, connect to the provisioned IP that you entered into the conversion field, and pull its LMS to terminate on from the AP System Profile.