What kind of clients are those exactly? Are those tunneled wireless clients?
Policy domain is an AOS 8 feature that is not applicable here. It was designed to share role information between separate clusters and/or standalone controllers, in order to enforce Role-to-Role (R2R) policies. As such this doesn't exist in AOS 10.
Within the same AOS 10 cluster, this information is synced implicitly. R2R should work for clients tunneled to the same gateway cluster except for a few corner scenarios depending on the traffic flow.
I don't think this has anything to do with AOS 10 per-se as whatever is preventing the R2R to work as expected would be the same in an AOS 8 implementation.
Hope the engineering ticket will provide you some deeper analysis on your setup.
------------------------------
I work for Aruba. Any opinions expressed here are solely my own and not do not represent that of Hewlett Packard Enterprise or Aruba.
------------------------------