Bug report: L2TP does not require IPsec
Recently I reconfigured my home network and I forgot to update my IPsec policy configuration, as a result my home vpn server was not negotiating any IPsec SA with the Foritgate vpn/router at work, but to my surprise they were able to successfully establish a VPN tunnel, an unencrypted/unprotected one. Granted it was a mistake on the other end, but allowing an unencrypted L2TP to establish is a security hole for a commercial (security appliance) product like Fortigate. It should be a straightforward fix by *requiring* IPsec for all traffic to/from port 1701.
