Aber: jedesmal wenn sich die WAN IP ändert (DSL reconnect) muß ich danach den HA PRoxy Service neu starten.

Edit, siehe hier:

So then, pfsense cannot be virtualized.

It can be virtualized fine. Just pass the NIC through instead of emulating one, or see if the VM can emulate a link-down event when the physical connection is interrupted.

Btw. there is a dedicated board for that kind of questions:

USB ethernet adapters are crap and the box itself is likely using a Realtek NIC, so one of the worst possible combinations for pfSense. Try to update the Realtek driver if it's a Realtek NIC (hint: search the forums) and use it with a managed switch as a router on a stick, this way you may get somewhat acceptable performance from it. But don't expect too much.

Did you add/enable any outside repositories or packages to pfSense?

I'm not going to explain IPv6 basics in a forum post, do your own research. Start with and the pfSense book. As for being a newbie, that's not an excuse for being lazy and entirely up to you to change.

The problem: Since I don't have a DHCPv6 service (using 'track interface WAN'), I can't find an option anywhere in pfsense that allows me to provide an alternate DNS IPv6 server to the clients.

Using "track interface WAN" does not prevent you from using DHCPv6 for the LAN. Did you even look at the "Services" -> "DHCPv6 Server & RA" settings, I bet not because the DNS settings on both DHCPv6 and Router Advertisements jump you right in the face there.

only thing new is this new gateway (

New gateway? You mean an additional LAN network? I guess it's time you post screenshots from your complete interface and firewall setup.

the test on deluge reports not open, never done that before.

That test is probably crap, trying to connect to those ports via the LAN interface. You need to test from the WAN. Read here:

I did the traffic shaping wizard not nothing at all worked well packet loss was higher

The wizards sets up the basics, you have to manually configure/tune the shapers/rules to match your use-case. Traffic shaping is not something you can setup in 5 Minutes and be done with it.

Well after spending alot of money upgrade to cat 7 and trying this out is all to my packet loss.

You can't fix packet loss on the WAN interface by upgrading your LAN. You really need to learn the basics of networking,

Sollte ich hier eine solche einmal gebildete Adresse bei der Schnittstelle fest eintragen, oder wäre es besser, die MAC eines der beiden Hardware-Ports einzutragen?

Weder noch, die korrekte Lösung ist keine Bridge zu verwenden sondern alles über einen ordentlichen Switch anzuschließen. Router Ports sind keine Switch Ports und sollten auch nicht so verwendet werden, dazu gibt es mehr als genug Threads hier im Forum.

Notiere dir die MACs der Qotom, starte diese neu und vergleiche ob sie sich geändert haben. Die Hersteller von solchen billig Kisten machen da oft irgendeinen Mist und verwenden die MACs mehrfach, oder lassen sie beim Systemstart zufällig generieren.

Im hoping I can just get away with everything in one box.

Forget it. You'll want at least a dedicated AP. And as for 4G, don't get an internal card, get an external modem that connects via ethernet. Everything else will always be a pain in the ass.

This isn't the requested functionality.

From the above:
The source code of those scripts can be adapted for adding firewall rules in other ways, but that is left as an exercise for the reader.
So start working and earn that money from your client.

