I changed on the Phase 2 on both ends:
Local network: "Network" and not "XYZ subnet"
And i disabled Hardware checksum offload.
Now i am able to reach the shares at least of one of the windows 10 machines. The other Machine still has a bitdefender firewall running, that i try to turn of, to see if that also works.
EDIT:
I was able to turn of the Bitdefender firewall again. Voila: Shares are accessible through Tunnel.
So for all Virtual Machine driven pfsense installations on Qnap: Turn of Hardware checksum offload and in IPsec tell him exactly what networks you are running. Do not trust the "XYL subnet" option.