Well it only took nearly all day to understand what @johnhooks and @scottalanmiller where talking about... but now I do.
It works because the RDS client is not pointing to yourservername.domain.com or even your internal IP address.
Instead the RDS client is told to use localhost or 127.0.0.1. The local machine then, through a forwarder put in place by PuTTY sends all traffic destine for PuTTY assigned port to PuTTY and PuTTY forwards the traffic over the tunnel to port 3389 at the address set in the SSL -L command previously run.
OK I understand.
THANK the Maker! -C3P0