@almabes:
Does pfSense have anything in its ARP cache for any of those CGN IPs?
It wouldn't, they're sourced from the Cisco layer 3 switch's MAC address, so it's routing it from somewhere behind it. Checking the Cisco is the next place to track it down.