Ok, it seems to work now. Here's what I did:
-installing the client 4.0.2(C)
-chown -R root:wheel /System/Library/StartupItems/CiscoVPN/
-chmod -R go-w /System/Library/StartupItems/CiscoVPN/
-same for: /System/Library/Extensions/CiscoVPN.kext/
-chown -R root:wheel /usr/local/bin (I only have the vpn stuff there)
Loading the kext then worked.
I added the line "USELegacyIKEPort=0" to my profiles (as seen at Cisco and MacOSXHints) and fired up the CiscoVPN GUI.
>> It's working!
So, I guess it boils down to a permission problem...