If you have vsz-h, confirm two point.
First,
show run lwapp2scg
LWAPP2SCG Configuration
--------------------------------------------------
ACL Policy : Accept all --------------> Have to Accept All.
Dynamic Data Transmission Port Range : Not specified
NAT IP Translation in FTP Passive Mode : Yes
ACL APs
Second, check whether the AP is located on staging-zone.