Am I to understand its OPNsense connected to ProtonVPN?
Have you configured OPNsense to allow LAN1 & LAN2 to talk to each other WITHOUT ProtonVPN first?
You need Outbound NAT rules that allows LAN1 and LAN2 to talk to each other.
Basically:
Source LAN1, Interface LAN2, NAT address LAN2. (for LAN1 to access LAN2)
Source LAN2, Interface LAN1, NAT address LAN1. (if you need LAN2 to access LAN1)
Then the Rules to actually route clients from LAN1 over the LAN2 gateway when the destination IP is LAN2, vice versa if necessary.
You wont automatically see LAN2 clients from LAN1, you will have to access them by IP address as broadcasts will not pass between the two subnets.