I'm going to be doing the same and the way I am going to be doing it is WAN -> Pfsense -> multiple vlans including wlan -> nethserver and nethserver stays on the inside aside from a couple of ports, as well as do a full AD controller off of nethserver.
My physical host setup is 2 gigabit nics...