I am seeing a strange behaviour with a AP in bridge mode connected to a switch in trunk mode.
I have a SSID with dot1x authentication and when a clients connects to this SSID with the wrong cert (it fails authentication) i see his mac appearing on the switch Mac table on the native vlan of the switch-AP trunk.
I am going to capture the traffic to see what it is sent but would like to know if this is a expected (in my view, strange) behaviour.