Hi,
i have a strange issue with an HSRP Setup.
I have two (S1+S2) 3560 as Core/Distribution Layer. Inter-vlan routing are enabled on both Switches. S1 and S2 are connected with an etherchannel over four fibre ports. S3 -S5 are the (L2) access layer.

Gi0/1 on S1 and S2 are L3 ports, connect to a Linux Firewall.
HSRP is enabled, S1 is the active router and the STP root bridge.
But, my monitoring via cacti show me, that the Gi0/1 on S2 is active, too! But it should not be active? Only if S1 fails, should S2 the active switch.
A client from the access ports on S3 - 5 gets traffic from the internet via Gi0/1 from S2. Gi0/1 on S1 is active too, but will send mostly traffic to the internet.
Why is S2 active and why route it traffic from the internet to the client?
kind regards