So here is a drawing of the network.
[image: 1554561731234-d51f6d59-d87e-475f-8485-ad799f7b3eef-image.png]
using ssh the client can connect to PF1, Server A, Server B, as well as PF2, Server C and Server D
using html the client can not connect to PF1 or Server A and B, but can connect to Server C and D as well as PF2.
the client can connect via OVPN to a client on the network behind PF2, with RDP and then use that client to connect to PF1, Server A and Server B with HTML through the IPSEC tunnel.
Both pfsense boxes have the default (everything to everything) OpenVPN rules.