I took one of the RAP's and connected it locally to the controller and it came up. I reprovisioned it after it upgraded and it connected. I then took it to the remote site and connected it and this is what i"m getting.
(Aruba3200-US) #show datapath session | include 4500
50.77.192.165 50.77.251.66 17 4500 1024 0/0 0 0 1 1/0 cc F
50.77.251.66 50.77.192.165 17 1024 4500 0/0 0 0 0 1/0 cc FC
(Aruba3200-US) #show crypto ipsec sa
% No active IPSEC SA
(Aruba3200-US) #show crypto isakmp sa
ISAKMP SA Active Session Information
------------------------------------
Initiator IP Responder IP Flags Start Time Private IP
------------ ------------ ----- --------------- ----------
50.77.251.66 50.77.192.165 r-v2-R May 29 09:58:41 -
Flags: i = Initiator; r = Responder m = Main Mode; a = Agressive Mode v2 = IKEv2 p = Pre-shared key; c = Certificate/RSA Signature; e = ECDSA Signature x = XAuth Enabled; y = Mode-Config Enabled; E = EAP Enabled 3 = 3rd party AP; C = Campus AP; R = RAP V = VIA; S = VIA over TCP
Total ISAKMP SAs: 1