NAT and IPSec/VPN are two unrelated issues. If you are doing NAT, you do have the add extra lines to tell the firewall not to NAT, but rather use the IPSec tunnel, for packets meant to go over the VPN (and not unecrypted out to the public).
MS Win2k does not support IPSec's tunneling mode, nor ISAKMP SA authentication. Until it does, I believe you only choice is to get the IRE client. Cisco ships it under their name as Cisco Secure VPN Client and can be purchased in 100 user licenses for ~$200.
The other solution would be to have a router or another PIX with the appropriate IPSec software running. This is ideal if you have a large number of users at any single remote site and makes it transparent to them.