So you are upgrading and then joining to your test setup, correct? Following Victor's suggestions should help. Be sure the local controller can communicate with the new master BEFORE attempting to create the master-local connection.
Make sure you are using the appropriate key on both sides.
On the master:
encrypt disable
show run | begin localip
On the local:
encrypt disable
show run | begin masterip
*if the master does not have a localip 0.0.0.0 ipsec ******* entry (0.0.0.0 indicating any local controller); it will need to have one specific to the IP of your new local.
Lastly, make sure you reboot the local (if you have not) after joining to the new master.
Assuming the above is correct, some additional troubleshooting commands from the master:
- show datapath tunnel table
...look for inbound and outbound IPSec tunnels
- logging level debugging security subcat ike
- show log security <#>
...look for IKE Phase 1 has mismatch (indicating wrong IKE passphrase)