Kindly refer to the below diagram. Under the split tunnel application, AP will use CAPWAP tunnel(not VPN) tunneled back to the controller to do the authentication. After the authentication is done, the CAPWAP would be split by data traffic and control traffic. And data traffic will leave locally.