Just one point, to have same mac on many vlans can be perfectly OK, the decision about "what mac to the need to send this IP packet to " is a per vlan question, not a network one. For example some vendors ( I know checkpoint do this ) you will see the same mac for every vlan for the same physical interface, for the checkpoint gateway. Of course if someone had connected one vlan to another like users sometimes do with edge points that's not so good.