If you have that situation, can you check if 'show mac-address' shows the MAC address that is listed for 1.2.3.5?
What I can imagine is that if the switch has an arp entry but no port in the the mac-address table, that it doesn't know where to send the packet. In that case it should either send it to all ports in the VLANs, or it should do an ARP first and then send it to the right destination (but it knows the mac already).
And yes, the thought that this may be related to dynamic arp protection or other protection features sounds reasonable. However, unless you can't quickly test by disabling arp protection and see if that resolves the issue, I would open a support case for this to have it be investigated because this sounds like something really undesirable which needs to be addressed.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------