For some context, I've been dicking around with computer hardware and software for some 4+ decades now, and would consider myself to know enough to be dangerous (though my knowledge of newer OS's is lacking). No formal training, I do not do this in a professional capacity and never have. A bit of a hack, I suppose, but it has worked out for me thus far...
Currently running some flavor of Netgear router and have been for about 8 years now. Not a particular fan of the brand and not necessarily my preferred choice, but it's what I could get at the time and it was the closest to suiting the needs then on short notice. It does alright and actually includes a number of the features in my list above, but the software interface is a bit clunky and feels limited (possibly by design). It is physically limited to four wired connections, which has now become an issue. While I could expand by adding a switch to one of the existing wired ports, I'd rather not go this route. I feel like there should be something better out there.
Neither, but I suppose I'm looking to apply similar logic to the connected machines. I'll do my best to outline and keep it orderly and coherent. May help, may not. Current network devices include:
Workstation #1 - used for "work work", needs internet access only, do not want it to see or access other network devices and vice versa. Aside from the physical power switch, I have little control over this device (I can change the desktop wallpaper!

), managed entirely by my employer.
Workstation #2 - new-ish, built by me a little over a year ago, runs Win 11 Pro. Rarely used at the moment, still in the process of killing off all the invasive M$ garbage on this one (what they're doing shouldn't be legal). Learning more about the group policy editor than I ever thought I would....
Workstation #3 - "demoted" about a year ago, still use this one daily and for most of my personal computing and design work, runs Win 8.1 Pro. Have been experiencing "forced obsolescence" through antivirus and browser software lately. Internet access is likely nearing an end for this one as a result. Upgrading the OS is not an option, partly because of the software running on it and partly because Microsoft sucks. No TPM, so no Win 11. Linux is not an option, either. The machine works, I'm not about to throw it way just because some M$ asshat says so.
Workstation #4 - older and less powerful than #3, this machine is in basically the same boat. In limbo at the moment, this one might get some flavor of Linux.
Laptop #1 - runs Win 10 Home (talk about a piece of shit! was purchased this way, preloaded...), handy when working on the vehicles in the garage or needing more portable design computing. Currently have to use this on Wifi only as it will automatically try updating to Win 11 if connected via hardwire - but not enough ports if I wanted to anyway. Suffers similar issues to the previous two running older software.
Laser Printer - currently on WiFi due to aforementioned port availability, has always been a bit glitchy with resolving IP addresses and occasionally needs a boot up it's ass. Assigning a static IP has helped, a wired connection would solve this. Should be accessible to all devices EXCEPT Workstation #1 - could never print properly to it anyway, thanks to my employers use of Citrix.
NAS - wired connection, accessible to all devices EXCEPT Workstation #1
3D Printer - connects via Wifi (in LAN only mode), no provisions for wired connectivity, access is only needed for my primary design computer, currently Workstation #3.
That may be, though would prefer to do in one if possible.
After going over my posted list again, I cleaned it up a little and reordered based on feature importance (1,2 & 3 are tied for 1st)
- robust hardware firewall functionality - not interested in nor do I use any shit M$ security software
- solid software interface - not interested in any kind of smartphone app access or control, if that's a thing
- 6-8 wired Ethernet ports
- WiFi capable - must be fully configurable and easily shut off
- must have the ability to block access to specific internet addresses, preferably with options for "by device" as well a "global", though I'm fine if the "global" must be achieved with repeated "by device" setups. More than one way to skin a cat, assuming this would be tied to firewall functionality
- logging of all traffic in both directions - can be volatile logging, mostly would be used to verify that implemented controls are working
- ability to set and schedule access times for specific devices connected - or I can just power those devices down or pull the Ethernet cable...
- physical format - table top unit or rack mount (1U) - I like the rack mount idea but functionality is more critical than physical format