Hi, thank you for your reply.
I have a split tunnel. I did not enter split routing, just left as default. I have created an SSLVPN policy, with default incoming interface of SSL-VPN tunnel interface (ssl.root), outgoing interface is internal, Source is VPN LAN IP range and user group.
Interestingly, I've discovered after the tunnel is open for about 15 minutes the RDP connection works just fine.