An Aruba AP will usually have a PAPI management session as well as a GRE tunnel per SSID for transporting wireless client traffic back to the controller for processing. For extra security when running connections over the Internet, an Access Point configured as a RAP (Remote Access Point) will first establish an IPSec VPN tunnel back to the controller. The secure VPN tunnel then carries the PAPI and GRE sessions between the RAP and controller.
The PAPI and GRE connections between the RAP and controller will be established via the inner IP address to ensure they traverse down the secure tunnel.