If you have an old computer, you could replace the firewall-gateway with an simple firewall distribution based on linux or *bsd with web-based configuration.
I've tried ipcop with great success, but it has some limitations (cant block internal access to internet without manual iptables-rules.
m0n0wall on the other hand can do pptp, ipsec, openvpn, very good filtering rules etc. But is a little harder to get up in 2mins...

Links:
http://www.ipcop.org/
http://m0n0.ch/wall/

I have a ipcop firewall/vpn solution up for a customer and has been running for a couple of years without any problems.

/Fredrik