Select Page

Install and Configure Pfsense 2.3.1

I had issues with my Cisco Router and I have come to the conclusion that it has completely failed. I had reverted back to my Virgin Superhub 3 that come with my Internet connection (200MB D/L 10MB U/L), I was reading the HomeLab section of Reddit (https://www.reddit.com/r/homelab/) when I come across Pfsense, a router/firewall solution that could be installed as a VM. So I decided to proceed with setting this up and I have been pleased with the results! It’s an excellent product so I thought I would create an install guide for the software.

You initially need to download the ISO from the Pfsense website. This can be found here – https://www.pfsense.org/download/ – Select the correct version of hardware you are planning on installing this on, either the x32 or the x64 bit version. Then select the mirror that is nearest to you for the fastest download speed.

Download Pfsense ISO - Install and Configure Pfsense 2.3.1

Once you have downloaded the file this need to be extracted as it comes as a .iso.gz file. This can be completed using 7ZIP as an example. You will now need to create a virtual machine, I have used the following settings. Recommended specs for the VM are around 500MB RAM and 1 vCPU, I had more resources available and as I will be using this as my primary router I wanted to make sure this has sufficient resources. I have also put this on SSD storage to improve the responsiveness of the VM, after all I will be using this as a router/firewall!

Pfsense VM Configuration - Install and Configure Pfsense 2.3.1

When you have configured this you will need to select Edit Settings and then Connect your ISO from a Datastore.

Attach ISO - Install and Configure Pfsense 2.3.1

Remember to make sure you select Connect at Power on. I would also advise removing the Floppy drive as this is not required.

At this stage I would advise to create the WAN Port group on the ESXI Host. You will need to assign a secondary adapter to this port group, this will be the network port that requires connecting directly to the router once we have configured the VM. You can create this by navigating to Configuration –> Networking –> Add Networking and select Virtual Machine Port Group. I would also recommend changing Promiscuous mode to accept on the vSwitch settings, this will be required If you are setting up OpenVPN, I will be creating a guide on how to setup OpenVPN so watch out for that shortly!

JACOB WAN Port Group - Install and Configure Pfsense 2.3.1

Navigate to Properties –> vSwitch then change Promiscuous mode to Accept as per the below screenshot –

Promiscuous Mode - Install and Configure Pfsense 2.3.1

This is now completed. We can now start the VM ensuring that the ISO is connected to the machine.

You can wait for the machine to Autoboot as this is the correct option.

Welcome to Pfsense - Install and Configure Pfsense 2.3.1

You need to press ‘I’ when this selection comes up so it enters installer mode.

Press I to Continue - Install and Configure Pfsense 2.3.1

Scroll down to ‘Accept these Settings’ and press Enter.

Configure Console - Install and Configure Pfsense 2.3.1

Select Quick/Easy Install

Select Quick Easy Install - Install and Configure Pfsense 2.3.1

Press Enter to select ‘Ok’ to continue.

Ok to Continue - Install and Configure Pfsense 2.3.1

This will now start to install the system.

Installing System - Install and Configure Pfsense 2.3.1

Press Enter to use the Standard Kernel.

Standard Kernel - Install and Configure Pfsense 2.3.1

Once completed the installer will prompt you to remove the disk. You should now remove this and reboot. The machine will reboot and you will be presented with the below –

Assign Interfaces to Pfsense - Install and Configure Pfsense 2.3.1

We need to select option 1 to assign the interfaces to Pfsense.

Note – em0 will be vmnic1 and em1 will be vmnic2. You can verify this by navigating to the VM Settings and selecting the network adapter. You will then see the MAC address as below –

View MAC Address - Install and Configure Pfsense 2.3.1

You can verify these MAC addresses to make sure that we are assigning the correct adapter to each interface.

We need to make sure that the VM has two NIC’s. One will be for the LAN interface with a local IP address IE 192.168.0.1 and the other will be for the WAN Interface with an external IP that will be provided via the router that has been configured to be in modem mode.

I have configured these as below, you’ll notice this VM does not have an external IP as I already have another Pfsense box running on my network.

Interfaces configured - Install and Configure Pfsense 2.3.1

You will now need to connect to the LAN IP to continue the configuration, I have done this via a VDI machine so I added a network adapter and added the IP address 192.168.1.5 – If you have a PC you can manually set the IP so you can complete this part of the installation, before changing the IP of the Pfsense box to your LAN requirements.

Pfsense Login - Install and Configure Pfsense 2.3.1

You will need to login using the default username and password which is below –

Username – admin

Password – pfsense

This will log you in and take you through the setup guide.

Pfsense Setup - Install and Configure Pfsense 2.3.1

 You can setup your Hostname and DNS Settings as per the below screenshot.

Pfsense Hostname and DNS Settings - Install and Configure Pfsense 2.3.1

Configure the NTP servers, I have left these as default apart from changing the Timezone to London.

Configure Pfsense NTP - Install and Configure Pfsense 2.3.1

The WAN Interface configuration can be left as default as we will be putting the router in to modem mode.

WAN Interface - Install and Configure Pfsense 2.3.1

Now configure your LAN interface, I would advise not changing this until you have finished the setup wizard as you also need to change the DHCP settings to reflect the new IP. (This is assuming you have DHCP configured on your router currently)

Pfsense LAN Interface - Install and Configure Pfsense 2.3.1

Type a password for the router as per the below.

Pfsense enter password - Install and Configure Pfsense 2.3.1

Reload the router to proceed with these configurations.

Pfsense reboot router - Install and Configure Pfsense 2.3.1

You can wait for this to reboot and it will come up with the completion page as below –

Pfsense complete - Install and Configure Pfsense 2.3.1

I would now advise to install VMware Tools before continuing with the networking configuration as we will be changing the network adapters once it has been installed.

You can complete this by navigating to System –> Package Manager –> Available Packages –> Open-VM-Tools

Select confirm as per the below screenshot to install the package.

Open VM Tools Installing - Install and Configure Pfsense 2.3.1

You will see that the install has completed successfully.

Open VM Tools Complete - Install and Configure Pfsense 2.3.1

I would advise now shutting down the VM and replacing the network adapters with VMXNET3 adapters, these have a lot better performance than the E1000 adapters.

The VM will ask you to re-configure the WAN and LAN Adapters. You will need to use the same ones as before, again these can be checked by viewing the MAC address of the adapters via Edit Settings on the VM.

The VM will now start and we will need to log back in to the console.

At this point you can change your LAN IP by navigating to Interfaces –> LAN

Note – You will need to configure the DHCP settings to reflect the LAN IP change, this can be completed in Services –> DHCP Server.

We now need to put the router in to modem mode. There are multiple different guides for this but I may create one for Virgin routers shortly. I will skip this step for now, I will assume you know how to complete this setup. This will be different for all types of routers.

You will need to connect the router to the correct NIC in the ESXI Host, this is the NIC that we assigned to the WAN Port group.

In my configuration I have this directly plugged in to VMNIC1 and my VMNIC0 is plugged in to my switch. You will need to reboot the VM for the Dynamic WAN IP to take effect. Make sure this is configured to use the correct port group that was created at the start of the guide.

This should be everything! If this is successful you should now be able to connect to the Internet via your Pfsense router. You will need to configure all of the devices to point to this new gateway, I have used the same gateway IP as my previous Virgin router so I didn’t have to complete this step. Stay tuned for my OpenVPN on Pfsense guide that I will be releasing shortly!

Pin It on Pinterest

Share This