I have several new R320 ap's and a vscg-E running 18.104.22.168.598 with AP Patch 2150 and cannot get these to join my VSCG and they are on the same subnet. Pretty frustrating . I have set the SCG to the VSCG's ip and also did a set director to the vscg's ip and they will not bring up an SSH tunnel to the controller. Installed unleashed on them and then uploaded the m back to 22.214.171.1240 and they will not join. Need help from support on this one probably.
I had some issues on Zone Director with the country code of the APs not matching the country-code on the ZD. Haven't seen this yet on SZ but are your APs a US Part Number by any chance (and your SZ configured for non-US devices?) Its a long-shot and I know you mention that you don't see the SSH tunnel established.. but just checking.
If you can mirror traffic on the switch hosting the AP, do you see it trying to initiate ANY connection to SZ?