[BUG] IDS/IPS ER707-M2 v1.0 (FW 1.4.2&1.4.5) - IDS engine silently drops ALL internet traffic
Hi everyone,
I am reporting a critical bug regarding the IDS/IPS engine implementation on the ER707-M2 v1.0, which persists across firmware versions 1.4.2 and the recently released 1.4.5.
Environment:
-
Router: ER707-M2 v1.0
-
Firmware: 1.4.2 and 1.4.5 (Build 20260722)
-
Controller: Omada Software Controller v6.2.14.11
Problem Description: Enabling the IDS module immediately results in a complete blackhole for all WAN traffic. The engine aggressively drops legitimate packets without generating any alerts, making the network entirely unusable.
Steps to Reproduce:
-
Upgrade ER707-M2 to FW 1.4.2 or 1.4.5.
-
Go to Settings > Network Security > IDS/IPS.
-
Enable IDS (even on the lowest/custom security levels).
-
Attempt to pass any standard LAN-to-WAN traffic.
64 bytes from 8.8.8.8: icmp_seq=410 ttl=117 time=16.453 ms
64 bytes from 8.8.8.8: icmp_seq=411 ttl=117 time=11.612 ms
64 bytes from 8.8.8.8: icmp_seq=412 ttl=117 time=12.515 ms
64 bytes from 8.8.8.8: icmp_seq=413 ttl=117 time=12.535 ms
64 bytes from 8.8.8.8: icmp_seq=414 ttl=117 time=11.558 ms
64 bytes from 8.8.8.8: icmp_seq=415 ttl=117 time=11.472 ms
Request timeout for icmp_seq 416
Request timeout for icmp_seq 417
Request timeout for icmp_seq 418
Request timeout for icmp_seq 419
Request timeout for icmp_seq 420
Key Troubleshooting Observations (to save L1 support time):
-
Silent Drops: The drops are completely silent. There are absolutely no logs or alerts generated in the Controller's Threat Management section.
-
Allow List Failure: Creating bypass rules (Allow List) for specific subnets or IP addresses is completely ignored by the engine. The traffic is still dropped.
-
Root Cause Isolation: This is strictly an IDS engine issue. Disabling the IDS module immediately restores full internet connectivity. Rolling back the router firmware to a 1.3.x branch also resolves the problem.
Impact: The IDS feature is currently unusable in a production environment.
Could this be escalated directly to the R&D team? It looks like a severe state table/Suricata engine misconfiguration in the recent firmware branches. I'm available to provide further debug logs if the engineering team requires them.
Best regards.
