Unfortunately you can't trust the green AP in the "AP Availability" report in case the AP is connected via VPN tunnel / tunnel with lower MTU.
The only thing that shows the correct info in my experience is the controller log.
If the tunnel MTU is not set correctly the last message (bottom to top) during the AP authentication is missing in that case.
So if you run into an issue with a remote AP always check whether you'd find the "blacklist success..." message in the log.