I'm a TSE and got a similar ticket which we got to the bottom of. Version 9.8.0.0.373
firmware has a DNS recursion bit bug (ER-1672), that may prevent new APs from
discovering the Zonedirector solely by DNS. The bug fix will be incorporated as
soon as possible.
The workaround in the meantime, is to employ DHCP option 43 with your ZD's IP
address translated by a tool like this link:
http://shimi.net/services/opt43/
Otherwise, you should also be able to SSH into the remote APs and issue the
'set director ip a.b.c.d' command with your ZD's IP address, then 'reboot' and
the APs should find their way to your ZoneDirector.
If DNS only discovery isn't the problem, then back to the VPN/MTU ideas.