Ok, check settings | connections | properties | advanced in secure client:
if the firewall-1 / secure client version are not too old, you should have the "connectivity enhancements" checked. You should try the NAT traversal options first as they are faster, otherwise try the visitor mode, which does ipsec over http.
Unfortunately however, if your admin as locked the secureclient configs at the firewall, you wont be able to modify them. If it is so, you should bring the issue to your network admin, as this is likely to prevent quite a few people from connecting...
Ammo
