Firewall rules for specific Vlan to VPN

unfortunately it is more confusing to me now.

to me this sounds like you have this:

(ISP modem IP — (MODEM interface (IP is what?) of pfSense , LAN IP — (UDM IP (not a device IP!))

if you use /24, is not a device address, but a network address. The UDM then cannot have specifically this address. there must be an IP address that the UDM uses to connect to the pfSense, which you haven’t mentioned. Otherwise, how do pfSense and UDM talk to each other if they are connected with interfaces on different networks?

I think you’d do yourself and the people you would like to help you a favor by drawing a network map as others here have done to be specific about the current setup. Some examples here: