Hi there
As the device in question is a firewall I wonder if the mac-address in question is a virtual mac-address, which is why you can't correlate this to a mac-address on a physical interface? This virtual mac-address can be shared between redundant firewalls, which may explain the log entry. In which case this would not strictly be a problem.
I would check how virtual mac-addresses are handled by your particular make and model as a first step.
Hope this helps. Please rate if it does.
Thanks