Hi @MaxUK
I'm using a pfSense behind my Internetbox - works like a charm with the DMZ-mode mentioned by @bitracer. This forwards every incoming request to your router - just like in bridge mode. The only difference is, that the public IP is not directly configured on the WAN interface of the Firewall/Router.
May I ask you for your usecase that would not work with this setup?
Best,
r00t