Could you show how you configured the subnets? For example, what is the combination of the parameters --ipv6_ra_mode and --ipv6_address_mode?

For example, from docs:

Setting DHCPv6-stateless for ipv6_ra_mode configures the neutron router with radvd agent to send RAs. The table below captures the values set for the address configuration flags in the RA packet in this scenario. Similarly, setting DHCPv6-stateless for ipv6_address_mode configures neutron DHCP implementation to provide the additional network information.

So, you could use tcpdump to see if RA are really being sent from network controller.

I suggest you to create rules in Security Groups to permit all network packets! So, you could debug to define if this really is a configuration problem. Otherwise could be just packets being filtered.