I have rap connected to the Controller(LOCAL) through IPSeC and that controller is connected to another Controller through GRE tunnel which has a dhcp server(vlan 2) for guest SSID on local controller. Local controller has another vlan(vlan 3) configured for .1x authetication. When a guest connects to ap(group guest) on the local controller it gets ip from the vlan 3.But ap in group guest2 gets ip from vlan 2.