# Install pfSense CE 2.9 step by step with the network installer and ZFS

Source: https://srvscripts.com/guides/install-pfsense-ce-2-9-zfs/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

pfSense CE 2.9.0, released on 20 August 2026, is delivered as a small network installer image rather than a full offline ISO. The installer boots, brings up a temporary WAN connection, and pulls the current package set from the CE repositories. That changes the workflow slightly compared with older releases: the box needs working internet access during installation, and interface assignment happens before the file copy rather than after the first reboot. This tutorial follows the installer screen by screen on a typical two-port appliance or a virtual machine with two NICs.

In short: Boot the pfSense CE 2.9 network installer, accept the licence, choose Install, assign the WAN interface (DHCP, static or PPPoE) and the LAN interface, pick the stable branch, select ZFS on GPT with the default pool name, review the…

**Short answer:** Boot the pfSense CE 2.9 network installer, accept the licence, choose Install, assign the WAN interface (DHCP, static or PPPoE) and the LAN interface, pick the stable branch, select ZFS on GPT with the default pool name, review the advanced options, then confirm and reboot. Log in to the WebGUI at https://192.168.1.1 as admin with the password pfsense and run the setup wizard to change it.

## Prepare the hardware and media

Write the installer image to a USB stick with `dd` or a similar tool, or attach the ISO variant to a VM. The installer needs a NIC with a route to the internet on whichever port you intend to use as WAN. Two physical interfaces are the practical minimum; on a single-NIC host you can run LAN on a VLAN, which the installer supports. Note the MAC address of each port before you start, since the installer identifies interfaces by driver name such as `igc0` and `igc1` and MAC address rather than by port label.

## Walk through the installer

After boot the first screen is the licence, followed by the choice between Install, Rescue Shell and Restore Config. Restore Config feeds a previously exported `config.xml` into a fresh install, the quickest path when replacing failed hardware.

The next screens assign interfaces. Pick the WAN interface and its addressing mode. DHCP suits most sites behind an ISP router or in a cloud lab; static needs the address, mask and gateway; PPPoE needs the ISP username and password. Then pick the LAN interface and optionally tag it with a VLAN ID. The LAN defaults to 192.168.1.1/24 with a DHCP pool of .100 to .150, and you can change both here. Setting them now avoids a clash with an existing 192.168.1.0/24 network at the site.

The version screen offers the stable branch, the previous stable branch and the development snapshot. Choose stable for anything that will carry production traffic. The filesystem screen then offers ZFS, which is the recommended choice, or UFS. Keep GPT partitioning. ZFS gives you boot environments, which let you roll back a failed upgrade from the boot menu, and it copes far better with unclean power loss than UFS.

The advanced options screen is worth reading rather than skipping. Leave the CE repository selection alone, keep the option to export the network configuration into the installed system switched on so the WAN and LAN settings survive the reboot, set the swap size if the box has little RAM, enable the serial console if the appliance has no video output, and leave the pool name as `pfSense`. A wipe option and a pSLC option exist for SSDs; only use pSLC on drives whose vendor documents support for it.

Confirm the summary and let the installer download and copy the packages. Remove the media when prompted and reboot.

## First login and setup wizard

Connect a client to the LAN port, take a DHCP lease and open https://192.168.1.1 in a browser. The default credentials are admin and pfsense. The setup wizard runs on first login and walks through hostname, domain, DNS servers, timezone, WAN and LAN settings, and finally the admin password; change it there. When the wizard finishes, go to System » Update and confirm the box reports 2.9.0 on the stable branch with no pending updates.

```
pfSense-upgrade -c
zpool status
zfs list -t all | head
```

Those commands, from option 8 in the console menu or over SSH, confirm the update state, the ZFS pool health and the boot environments created.

## Pitfalls to avoid

The most common failure is the installer stalling at the package download stage, which almost always means the interface chosen as WAN has no upstream connectivity, or DHCP was expected but the ISP requires PPPoE. A second trap on virtual machines is choosing interfaces in the wrong order; check the MAC addresses against the hypervisor’s NIC list. Finally, if the site already uses 192.168.1.0/24 upstream, LAN and WAN overlap and the WebGUI becomes unreachable, so change the LAN subnet during installation.

## Verify

Confirm a client on the LAN can resolve names and reach the internet, that Status » Interfaces shows the WAN with an address and gateway, and that Diagnostics » Backup & Restore lets you download `config.xml`. Store that file somewhere safe; with it, the Restore Config path on the installer rebuilds this firewall in minutes. For the next steps see [Configure VLANs on pfSense with a managed switch](/guides/pfsense-vlan-managed-switch/) and [Configure pfBlockerNG for DNS and IP blocking](/guides/pfblockerng-dns-ip-blocking/).

## Install pfSense CE 2.9 at a glance

**Official documentation:** [pfSense documentation](https://docs.netgate.com/pfsense/en/latest/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Configure VLANs on pfSense with a managed switch](https://srvscripts.com/guides/pfsense-vlan-managed-switch/) · [Troubleshoot MTU, fragmentation and slow VPN throughput](https://srvscripts.com/guides/vpn-mtu-fragmentation/) · [Set up HAProxy reverse proxy with Let’s Encrypt (ACME) on pfSense](https://srvscripts.com/guides/pfsense-haproxy-lets-encrypt/).

## Frequently asked questions

### Does the pfSense CE 2.9 network installer work without internet access?

No. The network installer fetches the package set from the CE repositories during installation, so the WAN interface must have working upstream connectivity. If the site is offline, install on a lab network first and restore the exported configuration on site.

### How long does a pfSense CE 2.9 installation take?

On a modern appliance with a reasonable connection the whole process takes roughly ten to fifteen minutes, most of it the package download. Slow links stretch that considerably because several hundred megabytes are pulled during the copy stage.

### Can I switch from UFS to ZFS after installing pfSense?

Not in place. The filesystem is chosen at install time, so to move to ZFS you export the configuration, reinstall choosing ZFS, and restore the configuration either through the installer’s Restore Config option or through Diagnostics » Backup & Restore.
