Issue with WPA2-Enterprise Authentication

So we've been running 9.7 EAP for a couple of weeks (this is on a SG450) and have run across a new issue; using the APX320 (in an earlier thread, discussed a provisioning issue which turned out to be a defective AP which Sophos replaced) Access Point.  Randomly WPA2-Enterprise authentication fails, and it takes a power cycle of the APX to bring that back up and running.  The AP shows as up and SSIDs not using WPA2-Enterprise authentication (plain WPA2 PSK) work fine.  The RADIUS server(s) we are pointing at (Windows DCs) are responding fine to the test button in UTM, etc.  and no changes have been made on those for many months.  Any suggestions?