Install a private CA root cert on all the machines in your network, and set up a router that's able to MitM TLS sessions to do deep packet inspection. Palo Alto Networks' kit has this kind of capability.
Most enterprise networks do this, but you'll have major issues with IoT devices and devices/apps that do certificate pinning. You'll probably have to put those on your guest network... Assuming you have one.