You have the same Source and Destination Endpoints in the rule.
Derp. I went and changed that, so now the Destination:Endpoint is going to the internal NAT address of the RRAS server. Still no change. TCP/UDP 1723 is specified in the service to be forwarded as well but its still coming through as a "warning" and being dropped.
The SOURCE endpoint should be <Any> or some IP address that is not configured on the firewall.
The DESTINATION endpoint should be the external IP of the firewall. The Redirect looks correct; this should be an internal IP address.
A packet comes in from source burb external and is destined to external burb also. The source of the packet is [some IP] and the destination of the packet is [some external IP of the firewall], initially. The destination IP of this packet is then changed to the internal IP of your server ("redirected").
Thanks Sleidl, great explanation. Got it working following your instructions.