The reason/answer probably is in the controller logs. Check 'show log all 1000' to see the 1000 most recent log entries on your controller. There check if you see indications of the RAP trying to connect, and if it is not check the console of the AP, if it is, there likely is an indication. As suggested, running out of IPs for the vpn-pool is a good candidate or issues with allowing the APs. Both should show up as events. I hope you use the built-in factory certificate (TPM), not a self-signed one, as self-signed will probably not work; but I would expect it not to work for any of your APs.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------