It is applied to all machines that the policy is applied to. You can make it a policy that is applied to the entire domain or only a few critical systems, or any combination of them.
You might also want to step back from requiring IPSec to requesting IPSec, except for those most "high security" servers. That way if both the client and server support the encryption it will use it, otherwise it will fall back to unencrypted for compatibility.
________________________________________
CompTIA A+, Network+, Server+, Security+
MCTS:Windows 7
MCTS:Hyper-V
MCTS:System Center Virtual Machine Manager
MCSE:Security 2003
MCITP:Enterprise Administrator