action=notrack in raw affects how the packets are handled in further layers of the firewall including filter, so it may have helped one thing but broken another one. After any change of a firewall of a device you are managing remotely, always try to establish a new management connection before closing the existing one (but it may not be sufficient, so safe mode and even scheduled scripts reverting the changes are useful too). But these are useless hints related to future, now you need to gain access to the hAP lite.
What is the own address of the device from which you are trying to connect to 192.168.88.1?
If it is the 192.168.1.116, disable the routing rule for 192.168.1.116 and try again.
Does the L2TP server assign any IP address to the L2TP client?
Also, can we switch to a more interactive channel? If so and you don’t want to publish your contact information in plaintext, use the approach and data from this post.