We at Network Translation build a NAT box called Private Internet Exchange (or PIX).
Works great. We've got about 30 in the field.
One unexpected benefit is the by-product of keeping information on TCP connections
thru the box. We can do higher-level packet filtering. Since we have all the knowledge
of connections that a proxy server has we can do better filtering. But, since we
wrote all the code from boot rom to command parser, we are as fast as a packet filter;
we designed everything around the packet path.
We don't use UNIX or any other general purpose OS (not even a real-time one.) because
the resources we needed to manage had to do with the traffic thru the box.
We've been shipping since December.
CTO Network Translation, Inc.