Thanks for the quick reply.
Yes, the LAN behind the MX is 192.168.1.0/24.
Yes, the PC's and the server point to the MX as the default gateway.
It's full tunnel.
The subnet I'm in before I connect to VPN is 192.168.0.0/23.
If I add a port forward, I can RDP without VPN no problem, but that's not the solution I want.