What hardware do I need?

Currently we have one CCR 1036-12G-4S, we have 2 major problems on current setup:
High CPU on PPPoE users connecting/disconnecting, freezing router.
High CPU on queueing (simple queues) in peak times.

We want to reduce resource consumption using second router.

Our plan is to separate services:

Router1:
PPPoE (~1000 users, RADIUS-client)
Bandwidth limit (dynamically created simple queues from PPPoE RADIUS)
Firewall (incoming local network traffic)
Connection tracking disabled
Must have 2 SFP ports

Router2:
NAT
Firewall (incoming internet traffic)
Failover between 2 WAN interfaces.
Connection tracking enabled
Must have 3 SFP ports

I need an advice on what hardware I need there.
Any suggestions?

Rather get another CCR or two and split your clients up by vlans.

What about NAT problem on router with lots of dynamic interfaces? (Connection tracking table gets recalculated on each connect/disconnect)