You have to test the web login.  that's key.  If you get in on the web, then it's not a login issue at all.
Once you determine whether it's a login issue or not, then you can move to the networking issue.  My MAS/UCA Server doesn't need a whole lot of connectivity to the PBX, so they can be in a different subnet.  However, the Clients and the MAS/UCA Server do need a lot of connectivity, that's why mine are in the same subnet.