<snip>Assuming I want to be able to run at / near line-rate, is the Xeon-D (1541) enough?
I am specifically looking at to leverage existing SFP+ ports and migrate to a LACP dot1q trunk of the above 3 'lans' onto the 'core' switch , which leads me to the server listed earlier (adding a SFP+ card) or looking at the over the top (1018D-FRN8T)https://www.supermicro.com/products/system/1U/1018/SYS-1018D-FRN8T.cfm
The 1018D is getting into the cost territory of a HPE DL360 class server (replace with your preferred flavor), but cooling and noise in the 'LAN closet' (which is close to accurate) is also a consideration, which leads to the Xeon-D options. I 'could' build my own
M-ATX/ITX solution, but a commercial solution and rack mount form-factor is preferredThoughts?</snip>
Your requirements mirror what I have in production right now. A few months ago I went with the Supermicro 5018D-FN8T and it's definitely more than able to handle that kind of load you mentioned.
It can also easily saturate my 250 Mbps upload using IPSec (haven't tried OpenVPN yet…) with plenty of CPU power to spare.
We had a thread going on there: https://forum.pfsense.org/index.php?topic=128646.15