It seems to be a bug in 6.0r1 through r3. Apparently, you need to edit the ACL to allow via IP, instead of using the hostname. Alternatively, as a workaround, you can go to "Resource Policies" -> "Terminal Services" -> "Options" and turn on "IP based matching for Hostname based policy resources". Apparently, they know of this bug and are working on it.