Symptom
9120AX: AP as supplicant failing EAP-FAST.
This can be seen if you have non standard config for the "authentication timer restart" value under the switchport where AP is connected.
This is happening because the 9120 AP is not sending EAP-Start packet after receiving EAP-Failure as a part of EAP-FAST.
This means that AP will not be going through dot1x until the timer of "authentication timer restart" expires. Only when the "authentication timer restart" kicks in, the switch will attempt to authenticate an unauthorized port and send EAP-Identity request, where the 9120 AP will respond with EAP-Identity response and should go through EAPOL process afterwards.
Conditions
AP acting as an 802.1x supplicant in order to authenticate against the RADIUS server.
Workaround
Use default or low "authentication timer restart" timer under the switchport config