I didnt see anything marked with red in the above? (Atleast when I was reading)
I have not really had to deal with Routers at all since we all access control and NAT with firewalls.
But to me it seems you have allowed the traffic to the actual IP address of the internal server rather than the public IP NAT IP address which in this case seems to be configured to use your FastEthernet4 interfaces public IP address.
There also seems to be a Static NAT configured for the same internal host so I am wondering why the Static PAT (Port Forward) is used?
I understand this is 2 years but maybe it help for others who knows.
My was solve by forwarding 443 along side with 3389.
ip nat inside source static tcp 10.20.30.20 443 interface FastEthernet4 443