Order a Hetzner Dedicated Root Server with no operating system, called a “Rescue Server”.
Purchase an add-on IP address for the server and request a separate MAC address for it.
Request a LARA Console session from Hetzner with a VMWare ESXi installer USB inserted in the server.
Once LARA Console is start and you are connected, set up RAID on your hard drives if you are going to use it.
Install ESXi to Hetzner root server, in ESXi Developer Tools enable SFTP or SSH.
Transfer your pfSense installation image and other guest operating system images to the server datastore.
Login to the ESXi host control panel using the vSphere Client or Web UI.
On the Configuration tab of the ESXi host, go into the Networking settings.
Create a new Standard Switch, name it “vSwitch1” by default with it’s network named “VM Network 2”.
(So now you should have a vSwitch0 on VM Network and vSwitch1 on VM Network 2.)
Create a virtual machine named “Router” on the ESXi host with 1 Core, 1GB RAM, 8GB HDD, OS set to “Other”, and choose FreeBSD OS.
Assign one of the Router virtual machine NICs to “VM Network” and the other to “VM Network 2”.
Assign a CD/DVD Drive to the Router virtual machine and point it to the pfSense image transfered to the datastore.
Power on the Router Virtual Machine and install pfSense with all the default settings.
(You will end up with one NIC acting as WAN using your Hetzner main IP and one NIC acting as LAN with no IP.)
Create another virtual machine on the ESXi host with your desired main operating system and NIC on VM Network 2.
Install your operating system to the “Main VM” and start it, you should have local network access but no internet access.
Open the Main VM’s web browser and go to the pfSense UI url, which is http://192.168.1.1. by default.
Login to pfSense with the default credenital “admin” and “pfSense”, start the pfSense setup wizard/walkthrough.
When setting up LAN, choose the option to Spoof MAC Address and enter the MAC from the Add-on IP bought from Hetzner.
(Do NOT manually set Static IP, use MAC Address Spoofing and ONLY enter the MAc Address… learn from my mistakes.)
Restart the Router VM – the Main VM should now have a local IP, an external IP, and internet access!