Eugen Leitl recommended a WRAP box running pfSense. Other than the lack of redundancy this sounds like it would be the ideal solution but he did seem to indicate it would probably take some work to figure out how to put all this together and get it running.