Unfortunately, the new services (caller id on-screen and remote dvr) require more than port forwarding…the router reports its status (including WAN address) to VZ and if it's IP is not on the edge WAN (VZ provided routable IP) it won't provide those services. There is a very good FAQ on dslreports about using another router with the Actiontec/Westell provided by Verizon:
http://www.dslreports.com/faq/verizonfios/3.0_Networking#16077
And a thread on the dslreports Verizon FIOS TV forum about putting your own router in front of the VZ router and retaining full functionality. Bit of a kludge but reading through the thread, there are a couple of ways to do it:
http://www.dslreports.com/forum/r23764746-Re-FIOS-TV-Central-website-access-with-Non-AT-Router
None of this is limited to pfSense, of course. And it only applies if you subscribe to VZ TV as well as internet. If you only subscribe to VZ FiOS Internet, you can use any router you choose.
Any router other than the VZ-supplied one connected to the ONT will require an ethernet connection, as omegadraconis points out. On the initial install, most techs will willingly activate the Ethernet port on the ONT if there's cat 5 available at the ONT location. If not, calling the FSC as he details works.
I'm using pfSense behind the FiOS-supplied Actiontec (Actiontec LAN ---> pfSense WAN) with no problem, even though it's double NATted. That said, I don't routinely do torrents or game, both of which can be adversely affected by this setup. I do have ethernet to the ONT and plan to try putting the pfSense box in front when I can get everything in place and plan for some down time.