Use
block log all to direct the blocked packets to the
pflog0 interface.
Run tcpdump on
pflog0 to view what is being blocked.
Code:
# tcpdump -eni pflog0
Generate some traffic from your LAN and tcpdump will give you some clues which rule(s) you will have to add.