First, on the ISA - open the gui - select monitoring - logging - click start query.
Make the RDP access attempt. What do you see appear in the realtime log?
Do you see the RDP traffic arrive and then get denied? If so, what rule is denying the request - the default?
Does nothing appear in respect to the RDP request? In which case the block is happening before the traffic even arrives at ISA.