IPSec. It looks like Microsoft released an update to IPSec which was installed (the machine pulls its updates via autoupdate). This then blocked all "dangerous" ports. Excellent. *sigh*