Your RPD are inside the IPSec VPN? If yes, you can't shape what's inside … You could, but you'd need 2 pfSense boxes at both end.
Like that :
Network #1 <--> pfSense (Shaper) <--> pfSense (IPSec) <--> Internet <--> pfSense (IPSec) <--> pfSense (Shaper) <--> Network #2The pfSense (Shaper) would have normal LAN/WAN scenario that the spaher is happy with and the pfSense (IPSec) would take care of the Internet connection and IPSec.
In this scenario you'll have to use 4 different Class C private IP range.
MageMinds