D & E
As per this official Cisco Document
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/mobility_groups.html
If you have a firewall b/w your mobility group members, open UDP port 16666 and IP protocol 97. If you are using encrypted mobility, open UDP port 5246 and 5247.
If you are using New Mobility, UDP port 16666, 16667, and 16668 are used.
For information about protocols and port numbers that must be used for management and operational purposes, see the Matrix Site
Further more looking at the Matrix Page
https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html
Source Dest. Protocol Dest. Port Src. Port Description
WLC WLC UDP 16666 16666 Mobility - non-secured
WLC WLC UDP 16667 n/a Mobility - secured - removed in 5.2
WLC AP UDP 5246-5247 n/a CAPWAP Ctl/Data
Since the question is related to controllers between each site (WLC < --- > WLC) then D & E is the most logical answer here.