OpenVPN communication problem

Hi,
I have the following configuration:
schema.png
Here are scripts:
MikroTik_OVPN_Client.rsc (1.2 KB)
MikroTik_OVPN_Server.rsc (1.09 KB)
MikroTik_Test.rsc (245 Bytes)

192.168.101.230 MikroTik_Test
192.168.101.240 MikroTik_Client (OpenVPN assigned from MikroTik_Server)
192.168.101.251 MikroTik_Client
192.168.101.252 MikroTik_Client
192.168.101.253 MikroTik_Server
192.168.101.254 MikroTik_Client

MikroTik_OVPN_Client and MikroTik_OVPN_Server are connected together through OpenVPN (ethernet mode) by external network (192.168.184.0/24, NetHostOnly from picture above). VLANs are used internally to separate networks within device.

All IPs in those devices which belnongs 192.168.101.0/24 network should be accessible from any device …

but:
ICMP(ping) from MikroTik_Test to 192.168.101.240 or 192.168.101.252 FAILS while 192.168.101.251 and 192.168.101.254 are OK (very strange cause if I close OpenVPN connection between Client and Server 192.168.101.252 becomes accessible from Test)
ICMP(ping) from MikroTik_Server to 192.168.101.240 or 192.168.101.251 or 192.168.101.254 FAILS while 192.168.101.252 is OK (at same device where 192.168.101.251 is inaccessible !!!)

Sometimes after restarting the devices, communication problems occur randomly to addresses 192.168.101.251, 192.168.101.252, 192.168.101.254 (all in Client) when accessed from Test or Server. They are never accessible in same time.

I tested it on newest firmware (7.13.2 CHR), but problem occurs on previous versions (including RoS 6) and physical devices.

What is the problem ?
MikroTik_Test:

# 2024-01-23 10:19:53 by RouterOS 7.13.2
/ipv6 settings
set disable-ipv6=yes
/ip address
add address=192.168.101.230/24 interface=ether2 network=192.168.101.0
/ip dhcp-client
add interface=ether1
/system identity
set name=MikroTik_Test

MikroTik_OVPN_Server:

# 2024-01-23 10:18:52 by RouterOS 7.13.2
/interface bridge
add name=bridge vlan-filtering=yes
/interface ovpn-server
add name=ovpn-test user=test
/interface vlan
add comment=ext interface=bridge name=vlan2 vlan-id=2
add comment=int interface=bridge name=vlan3 vlan-id=3
/interface bridge port
add bridge=bridge interface=ether1 pvid=2
add bridge=bridge interface=ether2 pvid=3
add bridge=bridge interface=ovpn-test pvid=3
/ipv6 settings
set disable-ipv6=yes
/interface bridge vlan
add bridge=bridge tagged=bridge untagged=ether1 vlan-ids=2
add bridge=bridge tagged=bridge untagged=ether2,ovpn-test vlan-ids=3
/interface ovpn-server server
set certificate=OVPN_test.crt_0 default-profile=\
    default-encryption enabled=yes mode=ethernet require-client-certificate=\
    yes
/ip address
add address=192.168.184.11/24 interface=vlan2 network=192.168.184.0
add address=192.168.101.253/24 interface=vlan3 network=192.168.101.0
/ppp secret
add name=test password=test profile=default-encryption remote-address=\
    192.168.101.240 service=ovpn
/system identity
set name=MikroTik_OVPN_Server

MikroTik_OVPN_Client:

# 2024-01-23 10:18:13 by RouterOS 7.13.2
/interface bridge
add name=bridge vlan-filtering=yes
/interface vlan
add comment=ext interface=bridge name=vlan2 vlan-id=2
add comment=int interface=bridge name=vlan3 vlan-id=3
/interface ovpn-client
add certificate=test@test.com.crt_0 connect-to=192.168.184.11 \
    mac-address=02:0D:E0:0D:3C:08 mode=ethernet name=ovpn-test password=test \
    profile=default-encryption user=test verify-server-certificate=yes
/interface bridge port
add bridge=bridge interface=ether1 pvid=2
add bridge=bridge interface=ether2 pvid=3
add bridge=bridge edge=yes interface=ovpn-test pvid=3
/ipv6 settings
set disable-ipv6=yes
/interface bridge vlan
add bridge=bridge tagged=bridge untagged=ether1 vlan-ids=2
add bridge=bridge tagged=bridge untagged=ether2,ovpn-test vlan-ids=3
/interface ovpn-server server
set certificate=test@test.com.crt_0
/ip address
add address=192.168.184.10/24 interface=vlan2 network=192.168.184.0
add address=192.168.101.254/24 interface=vlan3 network=192.168.101.0
add address=192.168.101.251/24 interface=vlan3 network=192.168.101.0
add address=192.168.101.252/24 interface=vlan3 network=192.168.101.0
/system identity
set name=MikroTik_OVPN_Client