Layer 2 Tunneling Protocol sends its header and payload in UDP packet. It is often used to encapsulate PPP traffic. L2TP does not provide confidentiality, integrity or authentication on its own. It relies on other protocols, such as IPsec to do that. IPsec provides a secure channel (ESP works in transport mode). L2TP provides a tunnel over the secure channel.
One L2TP endpoint is called L2TP Concentrator (LAC) and another L2TP Network Server (LNS). LNS listens on UDP port 1701 for LAC to initiate tunnel creation. Once it is done, the traffic inside the tunnel is bi-directional. L2TP provides reliability for control packets but not for data ones.