Guide: Getting Started on RHEL, CentOS and rebuild Linux Distributions

@Hack3rcon: When you add these rules, the kernel sends the packets to the queue waiting for Suricata to OK or reject them, so Suricata must be running.

You can add the --queue-bypass flags to fail open and allow things to continue to work when Suricata is not running, as I described here: Suricata-IDS conflicts with other security applications

May I suggest you get used to working with Suricata in a passive mode first? Make sure it alerts on what you want to block, then maybe move into an inline mode.