Hi there,
Could you confirm that Masquerading is enabled for the firewall zones under Network → Firewall → Zones? (Will be in General Settings for older firmwares)
Refer to this post for more information: RUT906 LAN Access from another subnet on a static route - #5 by MatasR
Masquerading will do a kind of NATting where it’ll translate the traffic going to the PLC so it looks like it’s coming directly from the router itself (basically LAN-To-LAN).
Let me know if this helps,
M.