Did you open all of these ports for controller to controller communication? This is from the user guide.
Communication Between Aruba Devices
This section describes the network ports that need to be configured on the firewall to allow proper
operation of the network.
Between any two controllers:
IPSec (UDP ports 500 and 4500) and ESP (protocol 50). PAPI between a master and a local controller is
encapsulated in IPSec.
IP-IP (protocol 94) and UDP port 443 if Layer-3 mobility is enabled.
GRE (protocol 47) if tunneling guest traffic over GRE to DMZ controller.
IKE (UDP 500).
ESP (protocol 50).
NAT-T (UDP 4500).