http://ciisqbg45nggykdl6rjdrq3wc64csga4vkphu66qsi65mypeitqedoad.onion/pfsense
If you select Manual Outbound NAT / Save, it will generate most of the rules needed. Then you can switch to "Hybrid Outbound NAT rule generation", then click the Save button, then Accept Changes. Next, (optional, but recommended) select all the entries with "500 (ISAKMP)" and delete them, since that's for IPSec and we're using WireGuard.