I'm having the same problem I can make a remote desktop connection from my mobile client to one of my servers and request the webpage of one of the printers in the Office.
I can't directly access that webpage from the mobile client.
As far as I can see, all the gateways are correct.
Firewall rules:
IPSec: Allow all on all for all
WAN: Allow TCP/UDP on port 1194 for all
LAN: Allow All from LAN Net to all
Maby I'm missing something?
//Edit:
When I traceroute a host in the office network from the mobile client, I get a response from the PFSense server and than from the default gateway of PFSense. So PFSense is routing the traffic the wrong way…
Doing the same traceroute from one of my servers, i get the PFSense host, than the router at the office and than the host I'm looking for.