I have been using the same config for a few years now but upgrading to the newest Mikrotik versions as they come out... and I think this may be contributing to my problem.
For the first time yesterday we setup a VLAN on an interface (as well as some queues) and since that time any user who VPN's into our network with a PPTP connection (assigned IP's from our IP pool) can only ping our gateway and other remote networks, they can't get to anything on our LAN (same interface the VLAN is on). If I disable the VLAN and move the rule to another interface OR remove the VLAN completely then reboot, everything is fine with the VPN. When we re-add the VLAN to the interface then reboot the VPN stays working but then the VLAN doesn't work -- it's one or the other.
We have some remote offices using PPTP connections but their IP's are not dynamically assigned, we have static routes and accept rules setup in firewall. They stayed up the whole time without a problem.