You may want to check out www.netoptics.com they have a good range of passive, active, and multiple port taps. Everything from DS3 to plain ole ethernet taps. I've fallen in love with my 10/100 port aggregator tap which actually has a buffer to hold onto traffic during a spike (so your IDS/monitor/sniffer/whatever doesnt get overrun and drop packets).

snort.org also has tap schematics for the build it yourselfers.... in a larger network with multiple vlan's (or just multiple switches) you may consider going with a multiport IDS/Sniffer system or tap, this will allow you to set up monitor ports on each switch and not waste fabric bandwidth on sending all monitored traffic to one switch and down to one switch port.

Which reminds me, if your on a switched network you WILL need to use the monitor port or port mirroring functions of the switches to push all traffic to one port.