Hi,
I want to thank you all for attending and focusing on my problem and for providing a solution that works in such a short time.
For now I will be using the workaround, which consist on separate IPv4 and IPv6 addresses for the blacklists. Soon I will apply the latest Suricata updates and that should be the final solution.
Before closing this thread, I have another question. Does Suricata actually has an engine similar to IPREP, but designed for domains instead of IPs? Something like DNSREP
. The goal would be to have IPs blacklists and domains blacklists, to massively block access, instead of creating separate rules for each domain, like some examples I have seen for sites like Facebook.
Thank you in advance