Since we got one handoff from ISP, Connection is going to switch and then distributing to firewall 1 and 2 however what are these IP's i am seeing when i clicked on switch port which is connected to ISP connection.
Given they are all showing the same MAC I'd say the switch is reporting on devices upstream. Is the a screenshot of the port that is connected to the ISP or one of your downstream firewalls?
Also I wouldn't recommend connecting a switch directly to an ISP like this.
Same thing with another ISP on switch 2
In case it helps, it looks like 00:00:5E is VRRP.
https://stackoverflow.com/questions/14710389/reserved-mac-addresses-some-are-assigned-anyway
So I'm wondering if the port configuration on 46-48 of the MS isn't setup properly and potentially leaking through the MS to the MX LAN ports. I would setup a separate VLAN that is not configured on the MX, and ideally not not part of the trunk ports to the MX.
What firewall is it? Looks like a Proxy-ARP misconfiguration.
We are using MX84
Hmm, what else has an IP on this VLAN? Do a packet capture on the ISP port and look for ARP packets.