That is what we've been finding out is a "Jack of all trades and master of none" solution.
- Routing (static only)
- Firewall (very rudimentary rules allowed)
- Traffic shaping - limited
- Client VPN - limited (all or none approach, can't give some clients more/less access than others)
- Web filtering - well, you mentioned it. Can't really get user reports...