Http://support.microsoft.com/default.aspx?scid=kb;zh-cn;818043
summary
Microsoft has released an update package to enhance the current function of the second layer tunnel protocol (L2TP) and Internet Protocol Security (IPSec) on the computer running Windows XP or Windows 2000.
This update contains improvements to IPSec to better support virtual private network (VPN) clients behind the Network Address Translation (NAT) device. If this update is applied to a computer running Windows XP, and the IPSec service does not start when the runtime error is encountered and the IPSec driver is running in block mode (the reason is that it cannot secure network communication security). (IPSec service is displayed as "IPSec Service" in the system service list.)