Both ways work. Suricata came first but is not as flexible.We recommend using aliases as you can use them in individual rules and refine them as needed.
I use them in combo..Alias block for a huge list of known offending countries: RU, China, etc. Then Suricata for finer work. This seems less resource intensive with no impact on throughput.
Quote from: Noctur on September 05, 2017, 04:59:38 amI use them in combo..Alias block for a huge list of known offending countries: RU, China, etc. Then Suricata for finer work. This seems less resource intensive with no impact on throughput.How di you managed to add the alias ?I believe you did not add IP for IP as alias ?