1) The document describes a vulnerability in IPSec/L2TP VPN connections where filtering UDP port 500 to drop IKEv2 negotiation packets allows an insecure L2TP connection to still be established, compromising confidentiality.
2) A simulation was created using 3 VMs to demonstrate exploiting this by capturing plain text traffic.
3) The only current workaround is changing the Windows VPN encryption setting, but a patch is needed to fully address the vulnerability.