If you AP's are in Tunnel mode, there would be GRE tunnel between the AP and controller. Also could be IPsec but I believe you need an extended license along with an intentional config forIPsec. I would wager that this behavior is the same in Mesh mode as it is for wired modes.
From the Aruba docs-
Tunnel: The AP handles all 802.11 association requests and responses, but sends all 802.11 data packets, action frames and EAPOL frames over a GRE tunnel to thecontroller for processing. The controller removes or adds the GRE headers, decrypts or encrypts 802.11 frames and applies firewall rules to the user traffic as usual. Both remote and campus APs can be configured in tunnel mode.