Looks like your client won the lottery with the ISP's router.
Is there a setting for DMZ on the Fast 5464? If so, DMZ should point at the GX50. All incoming requests from the internet then be directed to the GX50 and no port-forwarding rules need to be applied to the Fast 5464. Then set the RDP-rules on the GX50 only.
I know sometimes forwarding rules need to be applied. For security that's kinda a bad thing. Every port forwarded will show on a port-scan and the question is not "Why me?", bots scan the whole internet for open ports and try to break in, no matter where they find them.
I still would recommend to use VPN to connect to the network. If you can enable DMZ on the Fast 5464, it will allow you to have no ports exposed to the internet.