I'm sorry, I never saw your reply.
On the server running 360 you need to go into smart firewall settings and click
program rules. Then find the VNC server and change it from Auto to Allow.
The "allow" setting lets it recieve communications that do not originate from the server (incoming connections).
You also need to forward the correct ports to that system of using a router.
Giving trust to a system in the network security map only works for systems on the LAN, it can't be used for systems out in the internet.
Dave