Hi again,
Here are the IP4 routes from netstat -nrW:
pfsense A
Destination Gateway Flags Refs Use Mtu Netif Expire
default 194.XXX.XXX.253 UGS 0 168620 1500 vr1
10.0.20/24 10.0.20.2 UGS 0 20300 1500 tun0
10.0.20.2 10.0.20.1 UH 1 0 1500 tun0
10.0.30.2 10.0.30.1 UH 1 0 1500 tun1
127.0.0.1 127.0.0.1 UH 0 1 16384 lo0
192.168.0 10.0.30.2 UGS 0 107810 1500 tun1
192.168.254 link#1 UC 0 0 1500 vr0
192.168.254.204 00:0d:93:9d:fd:3a UHLW 1 392 1500 vr0 702
192.168.254.240 00:16:cb:a9:e8:67 UHLW 1 43 1500 vr0 437
194.XXX.XXX.224/27 link#2 UC 0 0 1500 vr1
194.XXX.XXX.225 00:XX:XX:XX:XX:de UHLW 1 19 1500 vr1 93
194.XXX.XXX.227 00:XX:XX:XX:XX:de UHLW 1 0 1500 vr1 98
194.XXX.XXX.254 00:XX:XX:XX:XX:0b UHLW 2 5955 1500 vr1 1189
pfSense B
Destination Gateway Flags Refs Use Mtu Netif Expire
default 220.XXX.XXX.241 UGS 0 81874 1500 vr1
127.0.0.1 127.0.0.1 UH 0 0 16384 lo0
192.168.0 link#1 UC 0 0 1500 vr0
192.168.0.1 192.168.0.2 UH 1 0 1500 tun0
192.168.0.193 00:16:36:53:c8:64 UHLW 1 5963 1500 vr0 1187
192.168.0.232 00:19:d1:61:a3:aa UHLW 1 10363 1500 vr0 939
192.168.0.233 00:14:2a:8a:1e:42 UHLW 1 7065 1500 vr0 1149
192.168.0.234 00:14:85:5e:9a:de UHLW 1 6628 1500 vr0 1144
192.168.0.236 00:08:a1:92:31:94 UHLW 1 1826 1500 vr0 1140
192.168.0.237 00:11:5b:f4:1d:ff UHLW 1 1010 1500 vr0 1200
192.168.0.238 00:16:76:c5:51:e0 UHLW 1 4272 1500 vr0 1145
192.168.0.239 00:19:d1:ee:1e:6a UHLW 1 2951 1500 vr0 1179
192.168.0.240 00:14:2a:8b:7b:b1 UHLW 1 8819 1500 vr0 1188
192.168.0.241 00:11:5b:f4:26:4e UHLW 1 845 1500 vr0 1198
192.168.0.242 00:14:2a:08:8f:56 UHLW 1 331 1500 vr0 797
192.168.0.243 00:16:76:c5:58:61 UHLW 1 4768 1500 vr0 1101
192.168.0.244 00:14:2a:8b:79:df UHLW 1 1715 1500 vr0 1156
192.168.254 192.168.0.1 UGS 0 0 1500 tun0
220.XXX.XXX.240/29 link#2 UC 0 0 1500 vr1
220.XXX.XXX.241 XX:XX:XX:XX:XX:1f UHLW 2 3755 1500 vr1 1174
I've obviously changed the external IP addresses, but the important information is still there.
BTW, aside from not being able to ping anything on network B from pfSense A, everything else is working fine in terms of cross-network access to internal servers and VoIP systems. Consequently, although I'm academically interested to know what the issue is, please don't bust a gut on this.
Thanks again.