On your Windows machine change or add the following registry item:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent\ DWORD (32-bit) "AssumeUDPEncapsulationContextOnSendRule" Set the value to 2
This allows the client orĀ server to be behind a NAT firewall.
Make sure you reboot after this change