I have no deep background knowledge of IPfire. I have run it in test only, and donated a couple of times in hopes of the fabled v3 or whatever the relevant number is. I noted the "my view on how it must work" restrictions on basic operation of the available zones and the since largely recanted attack on Wireguard as an alternative to OpenVPN. I remain aware of IPfire but otherwise am very happy with OPNsense at the edge and Mikrotik behind.
"