When you update an IPsec policy in Windows 2000, the IPSec Policy Agent logs the following in the System event log on the client:
Event ID: 156
Description: Matching filter exists in filter list.
This issue will occur if you change a security rule's action and you update the rule's IP filter list at the same time.
To workaround this behavior, change the rule's filter action and wait until the client computer updates the IPsec policy, before you update the rule's IP filter list.
NOTE: An example of changing a rule's filter action is changing from Request Security to Require Security.