3) Make named aaa authentication (and authorization and accounting if you need them) lists using each group. For example: "aaa authentication ppp RegularUsers group RegularServerGroup", "aaa authentication ppp SpecialUsers group SpecialServerGroup".
4) Apply those named lists to the right interfaces. "interface ABC", "ppp authentication RegularUsers", "interface XYZ", "ppp authentication SpecialUsers". Add ppp authorization and accounting lines if you need them.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...