what routers support hardware AES 256? I am not aware of any.
pfsense seems to be the right thing but what CPU? I don't want one that will clobber my electric bill.
Intel N3700 is a quad core that uses 6W and includes AES-NI instruction set. Pushes above 2Gbps seconds in pfsense tests using AES-NI (OpenVPN to add soon). Intel N3150 also a good choice.
Edit: Already posted above on the N3150 (sorry about that).
Future versions of pfsense are looking at adding Intel QuickAssist which could push AES-256 past 40Gbps rate with higher end processors. QuickAssist and AES-NI are included in some of the Bay-Trail Atom processors (4 and 8 core lower power versions).
I'm building a pfsense N3700 board as soon as I get the SuperMicro board. Overkill I know but I wanted to build something like this for a long time and I wanted it to be somewhat future proof (over 1Gbps with multiple ports for possible link aggregation to the switch if I so choose). I'll let you know the power it pulls at the wall when I get it running (waiting on SSD and board/cpu combo).
SuperMicro N3700 board with 4 Intel Gbs lan ports
8GB (2 x 4GB) of 1600 DDR3L 1.35V ram
128GB Sandisk SSD
Antec ISK-110 case with built in fanless 90W supply (92% efficient)
(I know I don't need the ram and SSD but since they were so cheap ($36 for ram and $35 for SSD), I thought what the hell. Lots of room for future expansion)