Well, the resolution was simpler than I expected.
I had the campus network folks look at the switch logs, and it appears that DHCP was being blocked at the switch port. They made that port "dhcp trusted" and all works as it should.
That's what I was hoping for – for such a simple configuration, it didn't make sense that I would have to set up VLANs in the firewall, since everything on the LAN side was on the same VLAN, and everything in the WAN side was on another. I figured it should have been just like a physical network as far as all the hosts (and pfSense) were concerned. But this was the first time I had dealt with a firewall that even understood VLANs, so I wasn't sure. :)
Thanks for the help!