Hope you doing good today!
Please check the following:
1. Verify if required firewall ports are opened for communication between the AP and the vSZ. If all the ports are allowed, then check if there is any packet drop seen on the firewall between the AP and the vSZ.
Reference document on the firewall ports: https://docs.commscope.com/bundle/sz-600-adminguide-sz300vsz/page/GUID-078C00BE-7543-4439-9326-F6509...
Please note, AP communicates to the control plane of the vSZ, hence communication should be allowed for the control-plane interface.
2. VPN MTU size: Try to reduce the VPN MTU size to 1200 and see if it helps. See if no jumbo frames are enabled on the uplinks.
Sarita Shekhar | CCNA | CWNA
Senior Technical Support Engineer,