I currently have the exact same question in my head. I think I’ll go the following route: Install opensense in a VM on my Proxmox host (it has 2 NICs) and just put my lab stuff behind it in it’s own lan. Everything connects to the router via firewall.
Benefits:
- The rest of the lan (e.g. partner’s devices) do not rely on my firewall working
- I don’t need to buy anything, I can switch to bare metal later if I need to and have figured out what exactly I need
Good luck!