Jonesy69:

Have you considered running Snort on a machine that doesn't have a stack bound to its network interface card? This would be a GREAT way of 'hiding' your IDS box, and also preventing it from overt attacks.

You can do this in the *nix world, but I'm not sure if you can in Windows. Anyone know for sure, one way or the other?

-C