@hda:
Put a managed switch, global rate limiting, between pfSense-LAN and your LAN-members.
That's a great suggestion, I hadn't thought of that. I was thinking I'd need a Managed switch in the near future anyway, they are fairly cheap now, and that would buy me some time to explore some budget upgrades for PFSense and let me keep using my service in a slightly reduced performance mode that I can control.
I also appreciate the other folks confirming it's time to update the hardware.