One other reason to virtualize at both levels - with a hypervisor at the edge, a separate, independent, non networked even, IDS is free, not running on your router and increasing it's complexity, dependencies, and vulnerability/attack surface. It's not the same as a tap, but there's definitely...