It is normal behavior for an OSPF router with an interface into a NSSA area to take the type-7 LSAs it learns from that area and convert it into a type-5 LSA before flooding it to other areas. When it converts the LSA from type-7 to type-5, it basically makes itself appear as the ASBR for other OSPF speakers in the attached areas. This is why you see the firewall interface IP as the "forward" address for this route. Regarding the cost of the route, it is also normal OSPF behavior for the cost of a type-1 external route to be the cost of the route plus the sum of the costs to reach the ASBR (your firewall, in this case). If you don't want the other routers to consider the cost to the ASBR in the route selection process, then you can change the way this route is injected into your NSSA from a type-1 external to a type-2 external. Hope this helps. -C
... View more