Hi experts,
So my company has nexus 5K as its data center switch.
We have a problem that there is a virus with ip address X.X.X.31. We have arp and mac address table that ip address and found that ip address is int the eth1/20 of our nexus 5K.
But we found that there is 2 mac address in that interface :
![eth.PNG eth.PNG](https://community.cisco.com/t5/image/serverpage/image-id/32688iCAAAE90237139392/image-size/large?v=v2&px=999)
And we also find that the other mac address is belong to UCS Server with ip : X.X.X.21.
Would you please explain and how to fix it?