Putting it in the DMZ allows all traffic which is less secure, but with ISA that should not be a problem, I wouldn't recomend it otherwise. It must be that your WAG200G is not forwarding the appropriate encryption protocol GRE, AH, or ESP (you haven't stated which at this point). The basic port forwarding of 1723 must have been working as you were receiving "verifying user name and password". It is possible this feature does not work on that unit, or were you using AH, which as mentioned is not supported.
Are you happy leaving it in the DMZ, or would you like further assistance?