It might simplify - and speed up - your protected LAN if you made your gateway machine a DNS server for the protected LAN. That would eliminate the need for an updated hosts file on each system. If the protected LAN is on a different IP network than the WAN, you won't need to worry about your automation machines getting to the WAN.
An easier way might be simply put a gateway/router between your gateway machine and the protected LAN. Plug the WAN port into your gateway machine, and a LAN port into your LAN switch. You can still get to the gateway machine, but you'll likely speed up and simplify things on the LAN side without spending much money.
An easier way might be simply put a gateway/router between your gateway machine and the protected LAN. Plug the WAN port into your gateway machine, and a LAN port into your LAN switch. You can still get to the gateway machine, but you'll likely speed up and simplify things on the LAN side without spending much money.