If the component of the forwarder on the router fails, you can bypass the issue.
Sorry for the late response. Yes that´s true.
I will look at it again when I have time. Thanks for all!
One more hint, for l2tp behind NAT scenario, we usually set the router's WAN ip(place ahead of the USG) on local policy, instead of 0.0.0.0
Just feel free to post your question if you encounter any issue.