Jan 24, 2018 · For the scenario you've described, disable the "block private networks" and "block bogon networks" options on your pfSense WAN interface, otherwise its firewall will block the packets. And maybe re-label it to something other than "WAN"; e.g. "SPAN"

(20180226 – This post has been amended to reflect changes in pfSense version 2.4.2 — iceflatline) This post will describe how to install and perform initial configuration of pfSense for use in a home network. pfSense (i.e., “making sense of packet filtering”) is a customized version of FreeBSD tailored specifically for use as a perimeter firewall and router, and managed almost entirely

On the WAN screen, accept defaults, except for unchecking Block private networks and Block bogon networks, and hit Next. Accept all defaults on the LAN screen, and hit Next. Set a strong password on the next screen, and let pfSense reload. Now you’re at the pfSense WebGUI Dashboard. It’s best to reboot pfSense before proceeding.

iproute xxxx(wan interface of the pfsense box , ip from 192.168.2.xx subnet)
make sure to uncheck the "block private networks" on the wan interface of the pfsense box , also you should disable nat on pfsense.

Configure the Wi-Fi Access Point with two or three networks, for example one 2.4 Ghz network for IoT devices, a secure Home Office network and a Private network. On the Wi-Fi Access Point, add VLAN tags (for example 20, 30, 40) to the different SSIDs.

RFC1918 networks. Block RFC1918 Private networks: [√] selected Block BOGONnetworks. Block bogon netwoks: [√] selected Select next tocontinue . Configure LAN Interface. If necessary, give the LAN interface a specific address here. Here we reserve no modifications for · LAN IP address: · Subnet mask: 24 One pair of options to note right at the bottom of the page are "Block RFC1918 Private Networks" and "Block Bogon Networks". RFC1918 private networks are networks which are not allocated to devices on the internet and should only be used behind NAT. These are, and