Yes, I know this is ridiculous, overkill and borderline insane, but so am I and my paranoia won't let me sleep at night if I don't build something like this. I will also let you know I am no network guy, so if you hear something ridiculous there is that.
The situation:
>I have 7 devices at home: 3 wireless shits and wireless ones. I also have two routers and a ONT.
>I fear at least 5 of those devices could be compromised now (doubtful) or in the future (probable), including one of the routers, which is a shitty ISP-provided one full of backdoors
>Long story short, two of those devices are operated exclusively by me, the rest are operated by my family as well.
>My trusted devices are plugged onto my trusted router, and the others are connected to the other.
>When I am using my devices, I plug my trusted router onto the ONT, and then unplug the untrusted router. The trusted router and the untrusted router have never been in the same network.
<I suspect some hypotetical hyper potent strain of cyberAIDS the untrusted devices could be capable of attacking and compromising the sadly untimely updated trusted router, regardless of VLAN setups, strong passwords, etc.
<I also suspect some of the websites my family could be visiting (think fishy Facebook advanced clickbait trash) could attempt to scan my local network for possible holes to inject the digital gonorrhea in my beloved machines
<What I want to do is to completely isolate the untrusted devices (even between them, so they can't conspire against me) on a physical level via some sort of hardware firewall/router/layer 3 switch that is capable of routing their connections through Tor or some VPN
<This magic box should be connected to a trusted router for WAN access, and reject any and all direct connections to itself or the trusted router except if coming from a special administration network interface/port
What I am attempting to do isn't very hard. Networks like pic related or bastion hosts are very standard and similar to what I want to do. The real problem is implementation. Basically, I require some sort of computer capable of:
>Low energy consumption (probably some ARM shit) because electricity be expensive here yo
>Having two or more Ethernet ports, preferably Gigabit Ethernet, because otherwise isolation will be pure placebo
>Be capable of running a modern distro in it (thought about NixOS because I will probably end up adding more subnetworks with similar needs and being able to deploy changes to all devices at once will be a fucking godsend)
>Be able to VLAN tag packets because my ONT is a bitch
>Preferably cheap. I can blow up some hundreds in this setup but I am sure it can be achieved with way less so I had rather not to
>Obviously this excludes (((CISCO))) shit
Any hardware or software suggestions, or tips I should take into account in my most retarded yet summer venture?
Also, stupid overengineered setups general.