Update/Case closed...

You can change the "Scope" of a particular Exception in the Windows Firewall.
Apparently the SQL 2008 install (or one of the Hotfixes that the install installed) changed the scope to "My Network only" on several port exceptions including RDP.

Here's the technet link I found that tipped me off.
http://technet.microsoft.com/en-us/l...1.aspx#BKMK_14

almost cocktail time...

csr