Thank you guys for all your answers!
Unfortunately we have come to the conclusion that pfSense is not mature enough for enterprise use in our company. I'm not saying it can't be used that way, but make it running on new enterprise hardware seems to be bothersome. Together with some other small, and less small issues, we decided to switch back to a hardware firewall; a cheaper and in our eyes more reliable solution which is less risky.
Maybe we get back on this decision some day, but for now it seems the best choice.