I had this issue with new default firewall in v6.40.3. There is a rule:
6 ;;; defconf: drop all not coming from LAN
chain=input action=drop in-interface-list=!LAN
As CAPsMAN's dynamic interface is new one and it's are not in interface list "LAN" this rule blocks communication between CAPs.