PepVPN/Speedfusion sessions can only be built between WAN ports on peplink devices.
So mobile Device #3 connected to the LAN of #1 would be able to establish its own encrypted speedfusion connection to the #2 Balance 380 (with the SF VPN target set as the B380’ WAN), but this traffic would not pass over the existing unencrypted SF connection since that provides routing between the LANs of the B380s…