Yes a drawing would be very helpful
But couple of things - if your using as just a "router", then your not using any firewall rules? And your not doing nat?
How do the devices in your live network route to the lab network, I would assume they are using a default gateway other than your wan interface of your pfsense VM. So you would either have to use host routing on the devices in that network - or their gateway would have to know to talk to the wan interface of your pfsense vm to talk to the lab network, etc.
where you say you can not ping from the lan (lab network I assume) interface – lets call live network address A, and lab network B -- how does your firewall (gateway of live network I assume) know how to get to network B? It would need a route to this network, if not its just going to go out your ISP connection which I would assume is its default route. So it would be unlikely you ping your live network firewall from lab network.