Hallo Frank :-)
i can't change anything of the firewall. Also the network is as it is.
My goal was to just establish a VPN-Tunnel from WAN-Interface of "pfsense B" to LAN-Interface of "pfsense A", which are both in the inner (trusted) network.
I missed to draw the "LAN" Interface on "pfsense A", which may mislead you… Also the "WAN"-Interface of "pfsense A" is not drawn, which is connected to "Firewall".