First, and most importantly, this community forum is supported by the community (both Aruba SEs and by customers and partners) on a volunteer basis, and should not be considered (and certainly IS not) a substitute for TAC/support. If you have a critical operational issue, you should contact TAC at 1-800-WIFILAN for immediate assistance and then your issue will get worked on and hopefully resolved to your satisfaction.
Secondly, in regards to your position that you provided plenty of detail. Your original post did NOT include the detail that your SSID and IAP management are on separate VLANs. That tells us a lot about the pathing for data when it leaves one IAP on user VLAN 66 and is destined to the IAP mgmt VLAN 99. So there IS routing taking place from the WiFi user VLAN to the IAP management VLAN, which could be telling based on your config.
What we would consider plenty of detail would be things like network drawings that show the topology of your network and where the IAPs are in relation to VLANs (for L2/L3), possibly the config from your VC to look at roles and policies, etc. However, it's certainly understandable to not want to post that kind of data, to wit opening a TAC case is the next vest step.
You have a pair of fairly experienced engineers with over 20 years combined with Aruba that were working on assisting you on this issue today, and I apologize you went weeks without a response, but again, this forum IS NOT an official support mechanism and if you are having technical issues that require remedy, the proper course of action is TAC. So sometimes support is a catch as catch can, and sometimes things go unanswered. Since our assistance isn't appreciated and you feel we haven't helped you, I would again suggest TAC and wish you the best. If you find the remedy with TAC, please feel free to post the corrective actions or diagnosis here for others. But that is up to you.
Sorry you are disappointed. Good luck and happy hunting.