PPTP Can access my routerboard but not private network

I have a pptp server on new RB433AH firmware 4.1 routerboard, I can connect to the pptp server from the net (ether3), but can only get access to the routerboard itself, not the rest of the private network (ether2). I am a little confused, tried a number of filter rules without success, I would like to allow rdp 3389 to a single machine in my private network. any hints greatly appreciated…

You need to set ‘proxy-arp’ on the interface that the PPTP server resides on.