You can have Anti-bot, malware, phishing, and content filtering on your whole network for free by using OpenDNS. Point your DNS in your router to 126.96.36.199 and 188.8.131.52. Create a free account at OpenDNS and you can select what you want filtered. I would select at least these:
You can then select what else you want filtered. If you have a dynamic ip, you can either put the OpenDNS updater on one of your endpoints or use the DDNS built into the shield. Not only have you dramatically increased your security, you should have a faster and more reliable network. ISP's are notorious for either slow DNS resolution or outages. This is why speed tests will often look fine but you'll still have slow browsing. I recommend everyone do this.
As for antivirus, ClamAV was on an earlier shield f/w, but was taken off until some bugs we're worked out. My opinion is AV is more efficient on endpoints because AV at the gateway chokes the network.