Will look into fwbuilder but so far was planning to go with a server distro (no GUI) and was hoping to get by using iptables directly for NAT. With regards to bufferbloat, I had run the DSL reports ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results