If you only configure a single interface, it will appear as WAN, then pfSense will allow access to the webgui via that interface by default. This is it's 'appliance mode'. As soon as you add a further interface, LAN, it will go back to acting as a firewall by default and prevent any access via the WAN. You should be able to connect via the LAN interface at that point though.
To prevent that happening add your own firewall rule to the WAN interface before you add the LAN interface. The rule should allow access to the webgui ports (80, 443) from devices in the WAN subnet.
Steve