pfSense and OPNsense are great FreeBSD-based options if you want to use pf without needing to craft your own pf.conf.
Also it's possible to extract the certs from some BGW models to use with wpa_supplicant and bypass the BGW completely.
Also it's possible to extract the certs from some BGW models to use with wpa_supplicant and bypass the BGW completely.