Sorry, I read over both this and the thread you referenced. Maybe I am just too old school and you are using newer terminology for the same thing, but I honestly could not follow along.
We use pfSense as the firewall in front of our web servers. It is free and open source. It also has the ability to install additional plugins through "Package Manager"
- pfBlockerNG to help manage other things. GeoBlocking, IP ban feeds, and such,
- WireGuard for VPN setups
Plus there are a variety of other tools for it.
www.HawaiianHope.org - Providing technology services to non profit organizations, low income families, homeless shelters, clean and sober houses and prisoner reentry programs. Since 2015, We have refurbished over 11,000 Computers !