I see this in the config
ip access-list extended LAN
permit ip any any
I suggest that you remove the permit any any from the ACL.
I wonder if anything shows up in the logs on the router when you attempt to start the VPN from an Internet source?
Perhaps it might show us something helpful if you turn on debug for address translation on the router and then attempt to start the VPN from an Internet source, and then look for any debug output.
Thank you very much for your reply.
It is working with removing permit ip any any, but I loose internet connection for the router.
any solution for that please ?