FirewallConnectionTracking show connections that should not?

In a typical schema:
One omnikti AP with several SXT conected. Omnitik with default forward disabled.

When I activate the Firewall connection tracking in one SXT, then I can see sometimes connections with “U” state from “CloudPublicIP → Client IP”, but this client IP doesn’t exits under this sxt, it is a client IP from other sxt client.

Is it normal? Why I can see this “U” connection in other SXT that is not the correct one (default forward in AP is disabled)?

Anyone can say me just if it is normal or not?
Thanks