@johnpoz:
If your getting dhcp from your old wifi router, then yeah its going to be broken, since most of them point their lan IP as your gateway, and many don't allow you to even change that.. So yeah not going to work as AP if you let it hand out dhcp, or its not really an AP and your double natting, etc..
To clarify, the AP(old router) will pass DHCP from pfSense when I have the internal DHCP disabled. Or it will hand out DHCP if I turn off pfSense's DHCP and turn on the AP's DHCP server.
I think you are getting at the crux, which is that the AP does not want to stop being a router and its own gateway (it has gateway capability because it is a Cradlepoint MBR1000 with WIMAX/3G/4G interfaces). However, it will allow me to create manual routing table entries. I'm not experienced in that area, but do you think there is a way to build a set of routing table rules that will force it to send all traffic through the pfSense box? n.b.- No wifi clients will require access to any other machine on the LAN; they just need to get through the LAN to get to the interwebs.