Yes you are right mick88, but the rules are only automatically created if you are setting up rules through the natting process. If you look under NAT you will see a check box that says something along the lines of check this box if you want to automatically create rule.
I think you mix up things: The checkbox in the NAT screen you mentioned has no effect on the automatic creation of the firewall rules (--> allow 1723 + GRE) when activating the PPTP-VPN server. To check this navigate to <your-monowall-ip>/status.php and look for the lines you see in the attached screenshot. You will see there is no difference whether you check/uncheck the box.
He states he is using the firewall as the PPTP server. If you look under the PPTP server setup, there is no automatic rule creation. It even say's Note: don't forget to add a firewall rule to permit traffic from PPTP clients.
The info about the rule concerns the
PPTP-VPN section not the WAN section of the rules. You do not need to add any rules to the
WAN section to make the connection work, because this is done automatically when you activate the PPTP-VPN server. You just need some rules to allow inbound traffic from the PPTP-VPN (as the note reminds you of).