That message in the event logs (invalid Message-Authenticator) is almost certain that the RADIUS shared secret does not match. If you say 're-adding' the key in the NAD, do you mean that it's gone? I've never seen such a thing. I would check the Audit log to see when/who changes the configuration because once entered, it should stay in there.
This may be something to further investigate with support, if you can't find out who/what is changing the configuration.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------