For suppose:-

This is the rule : src :10.x.x.x destination 10.1.1.1 - in the logs it is seen

logs:-
log1 : src 10.x.x.x destination 10.1.1.1[10.1.1.2]
log2: src 10.x.x.x destination 10.1.1.1[10.1.1.3]
log3: src 10.x.x.x destination 10.1.1.1[10.1.1.1]

how a firewall is redirecting to the other two IP address?

Anyone ? any idea about this traffic pattern?