In addition to what Andreas’ said, I know people used to use the Linux “bond” interface to bond the 2 incoming interfaces together. In fact it looks like Security Onion still provides this feature. I think this does limit the amount of tuning you can do with RSS queues and such, as Suricata would be reading off the virtual bond interface.
I think in high speed environments that port aggregator taps or packet brokers are now more common - where you tap 2 10Gb interfaces into one 40Gb interface for instance.
But I don’t think IPS mode will you provide what you’re after. In the af-packet ips and tap modes Suricata is a bridge passing packets, so the ordering is controlled. If both sides were being fed from a tap, the ordering would not be controlled and I suspect things won’t work as expected.