The samba firewall rule(s) are only important for file sharing, netbios, etc.
For RDC (remote desktop connection) you need to open port 3389 from a VPN Zone to the green on port 3389. That is the only port you should need.
Then, make sure you have name resolution for your client names. Its much easier to find the right client connection if they're saved with names rather than IPs. Then you should be up and running