You list 8 public IPs, do you have a /28 or larger? A /29 would only allow you a max of 6 IPs. If so, do you NEED a public IP on the servers themselves or will 1-1 NAT work? I know HTTP and FTP generally work fine with 1-1 NAT but Voip can be troublesome. If you can do 1-1 NAT then put both pfsense boxes on the WAN switch and they will both get a public IP. From there you would assign IPs via 1-1 NAT mappings to the various servers. This will still keep them protected by a firewall but of course hinges on that big 1-1 NAT issue. Otherwise I think you can do your original plan, you will want to turn off NAT and do manual static routes most likely. As for the services I'm not sure what is available besides snort.