Update:
It appears that the current Netgate image of pfSense, with it's "AWS VPC VPN Wizard", configures the IPSec connections in a way that is no longer compatible with AWS. I guess AWS changed something since this wizard was created. AWS said that both tunnels created by the pfSense wizard should not be active at the same time, and that one should be in standby. I opened a ticket with Netgate support about this on May 4th, and hope to get this resolved before too long.