I have a Linux router/firewall that handles inter-VLAN traffic. It also has a dedicated physical NIC to "send a copy" of part or all of that traffic out to an IDS. I d