Last Updated on October 5, 2020
- Order a Hetzner Dedicated Root Server with no operating system, called a “Rescue Server”.
- Purchase an add-on IP address for the server and request a separate MAC address for it.
- Request a LARA Console session from Hetzner with a VMWare ESXi installer USB inserted in the server. (Transferring iso over the web takes longer than LARA console is provided.)
- Once LARA Console is started and you are connected, set up RAID on your hard drives if you are going to use it.
- Install ESXi to Hetzner root server, in ESXi Developer Tools enable SFTP or SSH.
- Transfer your pfSense installation image and other guest operating system images to the server datastore via SFTP or SSH.
- Login to the ESXi host control panel using the vSphere Client or Web UI.
- On the Configuration tab of the ESXi host, go into the Networking settings.
- Create a new Standard Switch, name it “vSwitch1” by default with it’s network named “VM Network 2”.
(So now you should have a vSwitch0 on VM Network and vSwitch1 on VM Network 2.)
- Create a virtual machine named “Router” on the ESXi host with 2 NICS, 1 Core, 1GB RAM, 8GB HDD, OS set to “Other”, and choose FreeBSD OS.
- Assign one of the Router virtual machine NICs to “VM Network” and the other to “VM Network 2”.
- Assign a CD/DVD Drive to the Router virtual machine and point it to the pfSense image transfered to the datastore.
- Power on the Router Virtual Machine and install pfSense with all the default settings.
(You will end up with one NIC acting as WAN using your Hetzner main IP and one NIC acting as LAN with no IP.)
- Create another virtual machine on the ESXi host with your desired main operating system and NIC on VM Network 2.
- Install your operating system to the “Main VM” and start it, you should have local network access but no internet access.
- Open the Main VM’s web browser and go to the pfSense UI url, which is http://192.168.1.1 by default.
- Login to pfSense with the default credential “admin” and “pfSense”, start the pfSense setup wizard/walkthrough.
- When setting up WAN Interface, choose the option to Spoof MAC Address and enter the MAC from the Add-on IP bought from Hetzner.
- (Do NOT manually set Static IP, use MAC Address Spoofing and ONLY enter the MAC Address… learn from my mistakes.)
- Restart the Router VM – the Main VM should now have a local IP, an external IP, and internet access!
That’s it! The process really is simple, the main bulk of time spent will be waiting on OS iso’s to transfer to the ESXi datastore plus a bit of time for the actual OS installations.
Please comment below with any questions, suggestions, or anything else!
EDIT 04-28-18: This is one of the most popular articles on the site. It sits at the top of Google Search and has daily visits, which is rather surprising to me since this was more of a note to myself than a guide for others! However, since there is nobody in the comments calling me stupid, complaining, or asking for advice, then I assume it’s a good guide? ?
John started JSnowCreations as a place to post random tech guides and product reviews. However, while shopping for his daughter’s first “big girl” bed in 2019 he learned about the hidden dangers of fiberglass in mattresses. Since then, John has made it his mission to expose as much hidden fiberglass in mattresses as possible. His ultimate goal is federal regulations that ban fiberglass from being used in mattresses, or at least a law that require it to be listed in the material tags.
For me I had to go into the WAN vSwitch settings -> Security and choose ‘Accept’ for ‘MAC address changes’. Otherwise it wouldn’t work.
This is on pfsense? It must be a newer security feature that wasn’t around when I initially wrote the checklist! I’ll check out a newer pfsense version and update accordingly. Thanks!
thers a lot of gaps and assumptions in this, could you elaborate alot more especially , the config of the MAC t oNIc and when it should be done i.e. the post config of pfsense
Yeah sure – When first installing pfSense with two virtual NICs assigned from ESXi everything should be defaults and you’ll end up with one NIC acting as WAN and one as LAN. Here’s how it will look on the screen once pfSense is installed and restarted after completing the next steps:
Once you’ve installed pfSense and have started up a virtual machine that’s connected to it and logged in at
http://192.168.1.1
your LAN and WAN interface options should look like this:and:
It’s really not too crazy, I hope this helps!