bmeeks put a great guide together, a little dated but still a good thread…(thanks bmeeks!)
This is a more recent thread:
This will get you going...
My suggestions would be:
When you setup the interfaces resist the temptation to "Block Offenders" at the can use it as a IDS then move to IPS. It will block a lot! Use the "Snort VRT IPS Policy Selection" to start depending on your needs...i.e. Balanced/Connectivity/Security Use "Service_Watchdog" package as well in case it stops...I think any of the IDS/IPS packages use hardware make sure your setup is strong enough...not hard to setup! Requires some attention to get going...quite a few false positives to start that block traffic(hence start with IDS to start).
Good luck...