@rd:
Hi dreamslacker! Thank you for your reply!
Yes, media will be streamed by a Synology NAS Box (UPnP media server, NFS or CIFS). Actually I mainly bought it to improve data availability (RAID5), but it comes with several features one might want to use, once they're around. :-)
Currently my pfsense has 3 NICs, one is simply attached to a WIFI access point. I can keep it like this to reduce the CPU load of my future pfsense appliance. Will a D510 then be able to put through (from NIC to NIC) around 200 Mbps (if I understood your post right)?
I do not need caching, I only want the feature of forcing to login, as this prevents software from "calling home" and even can reduce the impact of malware that found it's way to my computer. Sorry that I forgot to write that earlier.
Currently my proxy (apache on a about 15 years old desktop) keeps a log file because there are some legal uncertainties in my sweet home country and keeping an access log can help you in case of false accusations. I thought that I would have to give up logging when using squid on pfsense, but having it run from a hard disk can be an even better option.
Thanks again for your help!
The D510 will be capable of 200Mbits/s throughput in total when filtering.
In any case at all, you can simply run the proxy without caching and also running a syslog server for logs if you wish to run embedded on a flash drive.
If you just want to force users to authenticate, then you'd use Captive Portal functions instead. Both are available for pfsense.