>One of the things I learned while building such a server-based box is that eBay is awash in counterfeit high-end Intel NICs.
Assuming you mean NUCs[0] and not NICs, I'm sure you're correct. That said, there are many other fanless miniPCs which are both less expensive and, as such, much less likely to be counterfeited.
>Regarding pfSense and OPNsense, I recently built and used a nice OPNsense box, including IPS, but decided to go back to OpenWrt for home use, because OpenWrt actually worked a bit better for the things I needed.
A fair point. The device I use as a router/firewall came pre-installed with OPNSense, which I immediately wiped and replaced with a vanilla Linux install and customised it to my own taste.
I mentioned OPN/pfSense not because I use them, but because they offer a fairly complete solution without having strong networking knowledge. Rolling your own is, IMNSHO, definitely superior to those, as well as to OpenWRT.
As for WiFi, I restrict my APs to just bridging to my wired network and have implemented strong egress filtering to control outbound access.
>I might use pfSense (or maybe OPNsense) router for a startup office of more than several people, though (until we can cost-justify a dedicated IT infra&support specialist). With OpenWrt on the WiFi APs.
That's not a bad idea at all. Although you might also consider one or more of the other distros/packages in the Wikipedia link[1] I included in my previous comment. Good luck!
[0] https://en.wikipedia.org/wiki/Next_Unit_of_Computing
[1] https://en.wikipedia.org/wiki/List_of_router_and_firewall_di...