We see a lot of HTTP traffic originating from our Aruba650 controller addressed to LocalHost:38950.
I have had aruba support look and they say they can not see any AP or Client generating this traffic, yet when I put wireshark on a mirrored port to the port Aruba is using, I get thousands of these:
Source Destination Protocol Info
captiveportal-login.mydomain.com Myproxy.mydomain.com HTTP CONNECT localhost:38950 HTTP/1.1