@Derelict
Derelict, thanks for the replay.
To begin with, I made a mistake. The address seen in the logs is a valid level-2 address. So normally I would not have started this topic.
Never the less, since I was thinking about this subject, I was wondering if there could be any non-physical “ip-object” which could be added / occur on the interface, added by the pf-sense router or firewall software or packages like avahi, igmp-proxy, pimpd, etc. (I am desperately trying to get multicast working across vlans, pimpd helps perhaps, imgp-proxy not).
That additional to the GW/interface as bonded to a physical interface or in my case a vlan on a physical interface or lagg. Of course the gateway sees every thing passing by on that interface as stream towards the firewall, I understand.
And next to that upstream there is the downstream, what is send from the FW-router towards that particular GW and from there towards the “physical” interface.
Louis