Hi,
We have seen a situation where "Apply local connection security rules" setting was set to "No" and this meant that IPsec can't be enabled in the firewall.
If anything prevents Microsoft IPsec from being setup in Windows, the Security Server pairing with IPsec can't work.
Check through your GPOs.
Mark