Hi Krishan,
This is configured in the AP Model Specific settings.
The configuration can be done in the AP group level or overridden in each AP configuration under Advanced Settings
This screen shot is from the AP Configuration where the group settings have been overridden.
You can configure the second (or other ports for H model AP's) as Access to allow untagged traffic from a device plugged into this port to be sent out the AP tagged as configured in Untag ID setting in the above picture..
The switch port the AP is connected to (via the required Trunk "wan" port of the AP) must accept this VLAN as tagged.
Leaving the untag ID as 1 will send the wired device traffic out the WAN port as untagged into the default VLAN.
You can also configure this port as "Trunk" to allow a VLAN switch connect to this port that will send multiple VLAN's through the AP. The untag ID can send untagged traffic from this switch into a taged VLAN egressing the AP if set to anyting other then 1.
Setting this port to General allows you to "prune" the VLAN's where all expected VLAN's must be added as Members.
This can be used where MESH AP's are used to link networks from one site/building to the main site.
You can also change the native/internal VLAN of the AP from 1 to any other VLAN by changing the untat ID of the WAN Trunk port. This allows VLAN 1 to be used as tagged if needed by your network - but this is generally not advised.
I hope this answers your question.