There is an underlying infrastructure called MultiPortal that allows multiple components to use the same port.
Depending on the specific URL accessed, the correct component will be called (Gaia portal, MAB, reverse proxy, etc).
Two components cannot share the same URL, obviously, and each one should be configured to use a unique one.
However, it can only use ONE TLS certificate, so your certificate needs to account for all the URLs that might be accessed.
Based on what you've described, it sounds like you need to configure the Mobile Access portal to use a different URL (either a different hostname, different URI on same hostname, or both).
IPS and AV scan the proxied traffic, as noted here: ATRG: Mobile Access Blade