Thanks for the AC-BNFA-NQ this seems to help us here as well.
I want to contribute something I observed and can reproduce:
Situation
HW (old PC) based pfSense in a branch office
Win 2012 R2 U1 based pfSense in our DC
Snort
HW based is running stable with AC-NQ even though it has only 2 Cores and 8GB memory at all
Hyper-V based is running on 12 Cores and 16GB memory, but Snort failed with AC-NQ, the AC-BNFA-NQ does the trick, now it can be not only activated (about 2minutes) faster on all interfaces, instead of one only, it now can be activated on all interfaces and it is running stable now for 3d, usually it turned itself off every 2h to 6h.
A strange side effect on IPSec stability? :o
We reported https://redmine.pfsense.org/issues/4790 (Titel: Established IPSec Tunnel refused transporting further traffic out of sudden.. it than refuses any rule based traffic to anywhere!).
Even though it should be impossible from my point of view, we observed that since the only configuration change on both tunnel ends is the Snort thing it seems to be an obvious side effect.
This seems to be fixed now as well - and I find this is 'a bit' disturbing..