The traffic for VLAN 2 will come out tagged on the ethernet port of the AP, the VLAN 1 probably will be untagged.
I would start by not using vlan 1; 2&3 will probably work, or 10&11, basically everything except 1 as how network devices handle VLAN 1 is quite different.
Then; it's recommended to separate VLANs for management of the IAP, that VLAN needs to be native/untagged on the port of your router; and the wireless networks, which need to be tagged.
For the ER, there are multiple ways of doing it, but probably creating bridges for the VLANs and then assigning them to the AP etherenet port is what you would like to do. The ER can be a complex device, and if you need help in configuring that, you may have more luck in a different forum.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------