@bmeeks I've tried every mode. They give the same result. I'm honestly considering running it bare metal on something but I love Proxmox and really like it virtualized.
I am not familiar with Proxmox. I use VMware products. An IDS/IPS can be very demanding on a system, but I would not generally expect a performance hit as large as you are seeing. If you want to run virtualized, I would try a VMware product such as ESXi (there is a free version you could experiment with). Many folks run pfSense and its packages on ESXi without issue. There have been quite a few reports of various issues on other hypervisors. Hypervisors will all use virtual NICs (unless you pass-through a dedicated hardware NIC to the virtual machine). How well the software undergirding the virtual NIC works with applications like an IDS/IPS is what determines performance.
Bare metal is always going to be faster than virtualization given the same underlying hardware. But do not expect full line speed with an IDS/IPS running with a fairly heavy ruleset.