Curious phenomenon regarding netmask/gateway?

Hello

We have an appliance connected in our network, where I think the network mask is wrongly configured (255.255.0.0 instead of 255.255.255.0 maybe), but I can’t view or change it myself.

This appliance was reachable nevertheless, so no one noticed.

The phenomenon is now, that in two recent situations, access to this appliance was partially lost: upgrade of RouterOS (from approx. two years old to 6.48? in June), and by replacing a faulty MikroTik CCR with the same config yesterday.

It’s then only reachable from within its VLAN, but not from other VLANs (the MikroTik is routing between the VLANs; the PCs and servers are connected to a VLAN-capable 48-port switch). Other servers in the VLAN - with known correct mask and gateway - are reachable, the issue is only with this one.

The current situation (only reachable from within its VLAN) is the one I understand - connections from other subnets are probably sent directly back to the IP in the other subnet, instead to the gateway, which doesn’t work.

What I don’t understand: WHY it worked before the “MikroTik incidents” (upgrade/reboots/replacement)?

After the problem was first noticed in June, the external admin of that appliance was asked to check/correct the mask and gateway, what he apparently did, because it worked afterwards again. Maybe in the meantime he applied an update and reverted to the wrong netmask, but still it’s obvious that this somehow magically works, until RouterOS is rebooted?

Does anyone have an idea/explanation for this behavior?

Check changelogs for bridge info: https://mikrotik.com/download/changelogs