I'm getting good at idiot questions.
My target system is getting viruses faster than I can delete them, so I though 'cool' I'll turn on the Wingate Firewall.
As soon as I enable it on any setting , my 'remote control' feature goes away. Can't get in via Gatekeeper and can't use VNC to get in, either. So I had the local people disable firewall and I got back on. I chose custom setting .. saw the ports I liked were open, added 808 and 5900-5910 (for VNC) and applied. I immediately lost Remote Control again.
When I looked at the CUSTOM settings, it looked pretty clear - firewall seemed to "understand" that all services specifically set up in Wingate were allowed and all others were denied .. so I thought adding 808 and 5900-5910 to be a simple fix
What did I miss?