Thanks Gents,
Ok that makes sense - as I do have several SSID's in NAT mode, and only a few light users which is probably why I have seen this for the first time. - as I thought that this was going to be the best way to isolate the users from (a) anyone else on the SSID and (b) the LAN.
Will have re-think this strategy - as I do need to be able to isolate the users, so will split them out via VLAN - which wasn't my preference.
Didn't see anything in the events log for either the AP or MX and unfortunately I didn't have the syslog running (fixed now), I suspect that this might have given me the address it was trying to resolve?
Is this the only way to get detailed security detail?
Thanks and appreciate the quick response.
Cheers,
Adrian