You should not change VLAN during a captive portal authentication, as the client will not know that it was moved to another VLAN.
Keep clients in the same VLAN, and your 'luck' in this case is that if you place the clients in your guest VLAN, the Instant AP will automatically proxy the captive portal traffic over the management interface to your ClearPass. But key is not to change VLANs during the captive portal process.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------