I wasted a number of hours on probably the same thing. Gear came on 8.7.0.0, upgraded to 10.4.1.1, factory defaulted and tried to use ZTP to central with port-channel right out of the gate. After a couple hours, running debugs on the firewall I will was looking at packet captures. It seemed as the same was occurring, dns, ntp, and some other traffic was successful. Activate would not provide the instructions to kick it over to central.
packet capture showed that tcp-3way handshake was failing. 9012 sent syn, activate responded with syn-ack, responded again with syn-ack. eventually RTO's appended and a retry event took place.
It was a huge headache as there was no reboot option, and I do not have PDU's I can kill power. After spending extensive time for smarthands at datacenter to get shipment, racked, console, for nexus vpc with a cluster of units. Here I am spending hours on why traffic doesn't get received on the 9012 when LACP was enabled.
After going into full-setup, waiting for reboot just to factory default and go back in ZTP mode. It is surely a pain and I am sure there is some sort of software issue at fault. There is no way I can debug in that mode. I was checking LACP counters and they were incrementing in both directions. fdb table looked fine.
Going through ZTP as an access port worked but although now I am trying to debug on why I cant connect successfully to central. It has partially logged in and the control-channel seems to show its up.
Defiantly not a fluid process for something that has been heavily pushed.