non of the windows default installations have a firewall installed.. worse still, u can't get any type of firewall or packet filter on the windows CDs... if u need some kind of protection, u may want to look at getting ZoneLab's ZoneAlarm... u may have heard of it..
securing windows is a problem.. but here are a few things u can do...
u will need to disable all the services u think u don't need.. trust me, there are many, but that depends on what u intend to with ya machine... for instance, if ya server is going to run some kind of database, u don't need to have DHCP server enabled.. or IPSec for that matter.. aside from taking up resources, u risk having unnecessary ports open...
then, disable NetBIOS servers.. unfortunately, i am yet to find a way one can communicate with other windows machines using anything other than NetBIOS... however, ZoneAlarm can help u solve this.. it will, by default, disable NetBIOS attacks/connections to your machine....
good luck