@J12t @davepeck my best guess is that it would forward anything through the gateway's known MAC to avoid someone on the LAN from snooping on you through ARP-based attacks.

One way to test could be to add a static ARP entry for your device's IP pointing at your router's MAC and see if it replicates the before you're seeing...

EDIT: I missed "iPad". Packet dump from your router if that's possible...