Slap on the pfblocker-ng package and you effectively have a souped up Pi-Hole in the router too. My TV at home has stopped showing adverts for certain streaming channels which is nice.
There are certain strong feelings against Netgate (nee Electric Sheep Fencing) which may or may not be justified. You have Opnsense as an alternative option - it's a very well thought of fork of pfSense.
There's also pfsense [1] and OPNsense [2] which are more geared towards business users, and personally not worth the effort for me to maintain at home, so I haven't looked into them as much.
[1] https://www.pfsense.org/products/
[2] https://shop.opnsense.com/product-categorie/hardware-applian...
2. install opensnitch or similar on 1.
3. route all traffic through 1.
4. figure out how to deal with rule management and new connection requests from 1 to wherever is most convenient for you.
bonus points for making it easy to install a cert on the machines in my network and capture/inspection of ssl streams.
alternatively, some cloud egress point i can vpn to with outbound firewalling/logging/filtering as a service. i don't want to think about it all the time, so either community driven filters or a managed service.
basically i'm interested in two things. catching malware on my personal devices and inspecting/defeating software that is gossiping too much about what appears to me to be private.