You could look for a WatchGuard firewall secondhand and use that in 'drop in mode' which uses the same IP address and range on internal and external interfaces and gives full firewall features. Drop in mode is designed to do exactly what you want.
What speed connection are you on? I ask about the speed because if you want higher than about 500Mbps you'd probably need a model with a fan (to be affordable) and that could be an issue for you.
Up to 540Mbps you could use a secondhand XTM 26 (no fan). They can be found on eBay for about £30-40. The XTM 33 (no fan) is similar (about £40-60) and runs out of steam at 850Mbps. A T50 (no fan) would set you back a lot more secondhand but does cope with full Gigabit throughput.
If a fan is no issue, an old XTM 5 series model would cope or the XTM 330.
Avoid anything called Edge or Core, and anything called Xsomething that isn't XTM.
You can look at comparisons of specs at
https://www.watchguard.com/wgrd-products/appliances-...