capsman over vpn

hi all,
I have a RB2011i in remote site, connected to HQ via sstp. ping time avg is 72ms, 4% lost.

Problem:
tried to connect it with capsman in HQ, but nothing happen. (nothing shows in both side logs except “..setting changed by admin”)
have 2 APs in HQ as capsman client working fine.

is capsman supported via vpn? or I should add additional setting?
2016-11-17_145032.png
thanks.

and problem 2: remote ap can’t use radius authentication (same under sstp vpn connection), in standalone mode(not capsman).logs keep saying auth time out.
a win2003 AD PDC work as radius server.
but the network has no limit on it, ping/tracert/telnet etc test all passed in both side.

capsman problem fixed. I forgot to allow remote tunnel ip input in hq firewall. :open_mouth: