because pfSense is inaccessible from WAN, I had to VNC in the VM and add a rule to permit my computer to connect to it from WAN. next that, setup was just about identical to starting on bare steel.
Irrespective of its https://freebookmarkpost.com/story17487675/open-source-firewall-an-overview