So you have this
setup.png
Not sure which network you have were exactly..
But if you don't want 192.168.2/24 (bottom network) from talking to 192.168.1 you would block it on the lan interface of pfs2
You would have allow rule to talk to pfs2 lan addres for dns, ping for example on the pfs2 lan rules
Then you would have a block rule to 192.168.1/24
Then you would have a any rule to allow clients to talk to the internet.. Blocking 192.168.2 on pfs1 lan would be completely pointless and never happen, since pfs2 is directly connected to it.
edit: Ah @KOM beat me too it, but he didn't draw a pretty picture like I did ;) heheheh