Access Points can be managed over a VPN. Assuming that these are split tunnels, you just need to add the 1.2.3.4 IP to each tunnel so that the APs can communicate to the UTM. That's the "magic IP" used by the UTM.
Cheers - Bob
Sophos UTM Community Moderator Sophos Certified Architect - UTM Sophos Certified Engineer - XG Gold Solution Partner since 2005