I have setup and unblocked RDP locally works, but remotely it is broken
I think the dnat rule should be external interface -> protocol ->internal interface -> your device.
Check that the "Ephraim Desktop" and "TP Link VPN" objects don't violate #3 in Rulz.
Cheers - Bob