First of all make sure that all your network connectivty is working very and as I can see from your scenario youhave 1 master 1 local and you want to terminate access point on local if everything works well and fail to master if local fail right?!
the best scneario is to setup tunnel normally between the 2 controllers typeing :
on Maste:
localip x.x.x.x IPSEC <key>
on local:
Masterip x.x.x.x IPSEC <key>
now you should note that the tunnel will be intiated from the controller interface IP for example if you use Iterface VLAN 30 as the controller source vlan it will be intiated from this VLAN
to verify the tunnel :
type on both controllers:
show crypto IPSEC SA
now lets get back to our main issue (AP fast Fail over):
you can do that through HA profiles you can use this tool to get CLI for many solutions and youwill find Fast fail over
https://ase.arubanetworks.com/
now create AP system and put in LMS <the local IP addrress>
and on Backup LMS <Master IP>
and check LMS preemption box if you want the access point get back to teh controller when it available back again
you will need centeralized license if you have no license terminated on local controller use centralized license to get license from Master
.
now on AP side on DHCP server that give IP to access points make sure to use Option 43 with the IP address of the controller (Local) so access point can discover the controller.
if you found my solution solvent kindly hit accept as a solution.