I'll be getting 4Gbps fiber next week (coming from 800Mbps Ziggo cable) and need some advice on what I need to upgrade in my home network to not have (m)any bottlenecks. All cables in my house are Cat5e now so I have some upgrading to do . Did my best to create a network diagram (see below). It's not the whole network with all devices, but the main elements are there.
My main question: what to buy as a gateway (Box 14 replacement)?
After reading Vrije Modemkeuze, Eigen Modem and Eigen apparatuur I have some questions left about choosing my own gateway and what works with KPN fiber, specifically about the hardware to choose for my needs.
ONT
I don't see a reason to replace the ONT, I was a bit surprised that it didn't have a SPF+ port but only RJ45, but as long as that is not bottleneck I don't see why I would replace that. I assume this will use XGSPON, but since I don't have KPN until next week, I can't login to the servicetool yet to check.
New Gateway/Router specs
I'd want something more advanced than the KPN Box 14: a more advanced Firewall, VPN, VLAN, Parental controls, DNS, DHCP (maybe replace the Pi-Hole), IDS/IPS. And it needs at least 2x 10GbE ports (a WAN and a LAN).
I would connect this directly to my switch, but optionally, this new gateway could take over the function of the Switch as well, in that case it would need to have 6x 2.5GbE PoE+ ports (in addition to the 2 10GbE ports).
Are there any specific (hardware or software) specs that I need to consider to make it work with KPN fiber?
(I specifically do not need VoiP, IPTV, Multi-WAN, Harddrives, port forwarding or Wifi capabilities needed).
Probably good to know is that I don't have a server rack space available, just a small closet near the front door with probably 20x20x30cm, so probably no room for a dream machine or similar.
Bridge mode/Double NAT?
If my info is correct, the Box 14 cannot be placed in Bridge mode. Adding an additional gateway would create double NAT which seems like something I should avoid, leading me to think I need to remove the Box 14 from the network all-together. Not sure if the double NAT is big enough a problem to go through the hassle of setting up PPPoE myself?
Some concrete hardware options
I was first thinking of the UCG-Ultra to complement the Unify switches but (weirdly?) those are limited to only 1GbE LAN ports. Not ideal to have that as a chokepoint at the beginning of my network.
A good alternative could also be the Firewalla Gold Pro, but that A) doesn't come out until the end of the year and is 8x more expensive that the UCG-Ultra.
Netgate 6100 + pfSense seems to fit the specs. Mikrotik RB5009 is missing a 10GbE port, the Mikrotik CCR2004 is too big.
Are there any other decent pre-built devices out there or is my only option to go the custom/homebrew route with something like a NUC running pfsense/opnsense/openwrt/... ?
Thanks for reading this far down and for any comments!
PS: if you have any suggestions for removing any other (potential) chokepoints/inefficiencies from my network: happy to hear them! :)