Hi, Mike, and welcome to the UTM Community!
The "trick" with Sophos APs is that they first communicate with the UTM by sending messages to 1.2.3.4 and UTM Wireless Protection intercepts that traffic transparently. Enable that in the remote router and you should be fine. Any better luck now?
Cheers - Bob
Bob is right, the AP when on the remote network cannot route traffic correct to the magic IP of 1.2.3.4.
You could do a number of things to ensure the AP can find home. Easiest way would be to add option 234 to your Server 2008 DHCP service to dish out the actual internal (LAN) interface of your UTM where you Access Points can lodge them selves for registration.
==
When in doubt, Script it out.