Key takeaways
- pfSense ships with a deny-all inbound policy on WAN and a "Default allow LAN to any" rule outbound. Rules are evaluated top to bottom and the first match wins, so ordering is critical, and a final
Blockrule withLogenabled is what lets you see what is actually being dropped. - On your very first login at
https://192.168.1.1, change the defaultadmin/pfsensecredentials in System > User Manager. Then move the GUI to HTTPS on a non-standard port (8443) under System > Advanced > Admin Access, keep the Anti-lockout Rule enabled, and restrict admin access to the single IP of your management workstation. - A VPN that carries no traffic is almost always a firewall issue: you need a WAN rule allowing UDP 1194 (OpenVPN) or 51820 (WireGuard) so clients can connect, and a rule on the VPN interface itself — it contains none by default, which means all traffic from connected clients is blocked.
- In a CARP high-availability setup, every interface consumes three addresses: the primary node IP, the secondary node IP and the shared CARP VIP (VHID 1 on WAN, VHID 2 on LAN), plus a dedicated link for pfsync and XMLRPC config sync. Clients and NAT must point at the CARP VIP, never at an individual node IP.
- Budget 2 GB of RAM and 8 GB of storage below 100 Mbps, but 4 cores, 8 GB and an SSD as soon as you target multi-gigabit with Suricata/Snort enabled. Intel NICs (
igb,em) are the most reliable under FreeBSD, and Hardware Checksum Offloading (System > Advanced > Networking) should be enabled except on Realtek cards, where it is a known bug.
Prerequisites
Before you start, make sure you have the following:
- Dedicated hardware or VM: 64-bit CPU (AMD64), minimum 2 GB of RAM, 8 GB of SSD storage recommended
- At least 2 network interfaces: one for the WAN (Internet), one for the LAN (local network). Intel cards (igb, em) are the most reliable under FreeBSD
- USB stick: 4 GB minimum for the installation image
- Console access: screen + keyboard or serial port for the initial installation
- A client machine: connected to the LAN to access the web interface after installation
Complete installation
Downloading the ISO
Get the image from Netgate's official site. Choose the AMD64 architecture and the USB Memstick format (VGA or serial depending on your console).
# Download the image (example with wget)
wget https://atxfiles.netgate.com/mirror/downloads/pfSense-CE-2.7.2-RELEASE-amd64.iso.gz
# Verify integrity
sha256sum pfSense-CE-2.7.2-RELEASE-amd64.iso.gz
# Decompress
gunzip pfSense-CE-2.7.2-RELEASE-amd64.iso.gz
Creating the bootable USB stick
# Linux / macOS - identify the USB stick
lsblk # Linux
diskutil list # macOS
# Write the image (replace /dev/sdX with your stick)
sudo dd if=pfSense-CE-2.7.2-RELEASE-amd64.iso of=/dev/sdX bs=4M status=progress conv=fsync
# On Windows, use Rufus or Etcher in DD Image mode
Installation wizard
Boot from the USB stick and follow these steps:
- Boot menu: accept the default boot or press Enter
- Copyright: accept the license
- Install: select "Install pfSense"
- Keymap: choose your keyboard layout (French ISO for AZERTY)
- Partitioning: select Auto (ZFS) for a modern system or Auto (UFS) for older hardware
- ZFS Config: Stripe for a single disk, Mirror if two disks are available
- Disk selection: select your target disk
- Confirmation: confirm and wait for the files to be copied
- Reboot: remove the USB stick and reboot
Assigning the WAN / LAN interfaces
On first boot, pfSense asks you to assign the interfaces:
Do VLANs need to be set up first? n
Enter the WAN interface name: igb0
Enter the LAN interface name: igb1
Do you want to proceed? y
Premium Content
This advanced tutorial is reserved for premium members.
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime