I suppose it is prudent for me to answer my own question

Here is what worked:
1. Erase any automatically created Windows Firewall rules that refer to the UI or Mail service. Do not try to make them work

2. Create a new rule, us the "PORT" option - then allow ports 25, 110 (or others that you need for mail transfer, POP, etc.)