What can the expected throughput be with BPI-R4; others suggested; with running Snort/Suricata on the same hardware? How about OpenVPN; WireGuard performance and which PCIe crypto accelerator hardware may provide an uplift in performance with those applications?
The R4 may satisfy most of your requirements but I suggest that you personally test and approve in detail the functionalities that you are going to need because you could find a black swan like me (I recognize that it seems that finding black swans is my specialty).