We recommend either Solaris 8 or FreeBSD 4.8 or 4.9. These have both proven stable in our deployments. Your mileage may vary.
The server must have two NICs. One is for sniffing, and the other is for management. Again it is imperative that we not contaminate our Darknet with legitimate traffic, to include our own management traffic. In our example we pick FreeBSD 4.8 and assign the two NICs thusly: