What I did was to create an alias for each game/game service, with all their port numbers, for the firewall, then created a rule using each, to keep things tidy and easy to change per service if they change ports. I tested with that only, no snort or squid or anything else. Once all was working correctly, I then added squid and squidguard. Once that was tuned, I added snort and tuned that up. If I had put all three in there at once I would never have been able to figure out just what was doing what if something wasn't working. So I would disable Suricata or set the default allow-all out the firewall lan interface, and test. If it works, at least you have narrowed it down to what you had disabled, firewall rules or Suricata.