If I understand your question correctly. You define and seperate traffic to each context by vlan id's. You would create sub-interfaces in the system context and assign a vlan there. Then assign that sub interface to a context.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...