suricata does not drop any packets from and to the firewall. That is caused by not having the RED IP address space (including aliases) in the HOME_NET variable. Should any static routes be in here, too? Please also merge my patch to scan any outgoing packets: https://patchwork.ipfire.org/patch/2054/
Merged: https://git.ipfire.org/?p=people/stevee/ipfire-2.x.git;a=commit;h=17c2c09bcc50376ef805a194eec8688a3dfcbc29 Fixed: https://git.ipfire.org/?p=people/stevee/ipfire-2.x.git;a=commit;h=23c0347ac5d386e215c56ae9fa3af97e66f1c23f