ZimaBoard remains a natural small x86 router platform because it has two Ethernet ports and can boot a standard 64-bit firewall OS. The 2023 IceWhale tutorial demonstrated the basic architecture correctly: install pfSense, dedicate one NIC to WAN and one to LAN, configure DHCP/firewall rules, then manage pfSense from its web interface.
The screenshots and download instructions are now historical. Netgate's current installer uses modern AMD64 installation media, and current pfSense guidance requires changing the default administrator password rather than leaving admin / pfsense in place. Treat the source as hardware/topology guidance, not a frozen pfSense 2.7.0 installation manual.
Two NICs Are the Minimum Practical Router Layout
For a simple home-router build:
- WAN → modem/ONT/upstream network;
- LAN → switch or local network;
- ZimaBoard storage → pfSense system/config only, not primary NAS duties.
Additional VLANs can share the LAN NIC through a managed switch, while more physical zones require additional supported NICs.
Use the Current Netgate AMD64 Installer
Current Netgate documentation says AMD64 Memstick USB is the normal installer for most third-party x86-64 hardware.
Use the current pfSense installation documentation.
Assign WAN and LAN Carefully
During initial console setup, identify which physical NIC goes upstream and which serves the trusted LAN. Reversing them can put the management interface on the wrong side of the firewall.
Label the cables/ports once the installation works.
Change the Default Admin Password Immediately
Netgate still documents the factory software credentials as admin / pfsense, but explicitly warns users to change the password immediately. On modern pfSense Plus releases, the setup wizard requires a non-default password.
Configure DHCP and Firewall Rules Deliberately
pfSense is the network security boundary. Confirm the LAN subnet, DHCP range, DNS behavior, outbound NAT, and only the inbound rules you actually need. Port forwarding should be added service by service, not as a broad expose-everything rule.
Bare Metal and Virtualized pfSense Have Different Failure Modes
One source user could not complete direct install and instead ran pfSense under Proxmox, valuing snapshots/backups. Another reported pfSense+ running smoothly on ZimaBoard for months.
Bare metal is simpler for a dedicated router. Virtualization adds snapshots/flexibility but also makes Internet access depend on the hypervisor, bridge configuration and host boot.
Back Up pfSense Configuration
Once WAN/LAN, VLANs, DHCP, certificates and firewall rules are working, export the pfSense configuration XML and keep it off the router. This reduces recovery time after storage failure or reinstall.
Avoid Combining Critical NAS and Router Roles Casually
If the same physical device is both your only router and your storage server, reboots, experiments, disk maintenance or hypervisor issues can take both network access and NAS services offline at once.
For a household that depends on Internet connectivity, a dedicated router role is easier to reason about.
Confirm ZimaBoard Boots from the pfSense System Disk Reliably
One later source user noted that they sometimes had to select the pfSense boot device manually from BIOS. After installation, power-cycle the ZimaBoard—not only reboot it—and verify the firmware consistently selects the intended pfSense disk.
If boot order is not retained after complete power loss, diagnose the firmware/CMOS behavior separately rather than assuming pfSense itself failed.
Plan Firewall Updates Before Applying Them
A router update interrupts Internet access. Export the configuration, read current pfSense release notes, and schedule upgrades when a short outage is acceptable. If the router is remote, ensure you have a recovery plan before changing interface, VLAN, or package configuration.
Router Features Increase Resource and Complexity Requirements
Basic NAT/DHCP/firewalling is lightweight. IDS/IPS, VPN encryption, traffic inspection, DNS filtering, many VLANs, and high-throughput packages can require more CPU/RAM and can reduce line-rate throughput on older hardware.
Size the workload based on the enabled services rather than assuming every pfSense feature has the same cost.
Never Manage pfSense from an Untrusted WAN Interface by Default
Keep the WebUI on the trusted LAN or a deliberately secured management network. If remote administration is required, prefer a VPN or another tightly controlled access path rather than exposing the firewall GUI broadly to the Internet.
ZimaBoard pfSense FAQ
Can ZimaBoard run pfSense?
Yes. The source includes successful community reports as well as the original IceWhale installation tutorial.
Should I use the old pfSense 2.7.0 download screenshot?
No. Use current Netgate AMD64 installation media.
Can I leave the default pfSense password in place?
No. Netgate explicitly says to replace it with a strong administrator password.
