"intnet as the internal network for those vms"
This is gibberish… intnet? Not a term...
"but no other machines on the lan"
Pfsense would have ZERO to do with lan devices talking to each other.. Pfsense is a router/firewall - not a switch... Devices all on the same network 192.168.1/24 traffic would not go through pfsense unless it was setup as a bridge..
"but then I fired up another machine on the intnet"
Again not sure where you are getting this term "intnet" it is not a networking term.. Do you mean internal network? internet? What does intnet mean in your context?
Pfsense can for sure just route.. But why would you not firewall as well.. If you want to firewall/route between 2 networks and not NAT (network address translation)… Those would be how pfsense would do it between 2 lan networks.. It would really really help if you drew up your network as you want it to be so we could understand what your trying to accomplish vs using some nonsense term.. Been in the biz 30 some years and I not sure what you mean by intnet.. I would guess either internal network or internet.. But can not be sure from your context, etc.