Not only would a Raspberry Pi be severely under-powered for routing even a small home network, in no way does monitoring that "goes to and from your LAN" defend against an adversary Snowden warns about.
> Could also put in an entirely passive NIDS on a physical layer in-line with your network’s service entrance. Very difficult for anyone to defeat, when done right.
Again, I'm not sure what threat model you think this defends against, but certainly not a three letter agency intent on either tailored exploitation nor passive monitoring of your inbound and outbound network traffic by the same actor.