I have a list of url that need to be blocked and a list of ip addresses.
How to do it?
Using Squid Proxy or you write custom rules for Suricata IPS like in the App detection rules.
Block rule(s) with Alias(es) won't work?
Not for URL
Problem? Because I'm using such setups for some years now....
https://github.com/StevenBlack/hosts
That's what I plan to block.
I did not find a convenient way to add the entire list at once.
Who else has used?
You probably need to parse it with external Script so it fits the URL table format