When trying to use RDP, set pfSense to log connections for the port and then try to connect while logged into the firewall and see what happens, if you cant do both at the same time then while at the location go to grc.com from any computer there and under services click shieldsup!, scroll down and click proceed and then type in the port that you want to see the status of (open,closed,stealth), in this case 3389 and click "User Specified Custom Port Probe". If it says you failed then you have succeeded, the port is open to all to see.
Things that could be blocking RDP from working in addition to what CMB has stated:
Snort
Firewall port forward rule incorrect
IP address of the system you want to RDP to has changed