1) The network shim option is supposed to present itself if you create a "noisy" installation agent kit. I have yet to see it in either 188.8.131.52 or 184.108.40.206. I opened a service request (603331301) on it.
2) Since 1) does not work, I don't believe 2) is possible for now. I did read in an earlier post that it is possible to use a registry setting to disable but I haven't tried it.
3) Security levels relate to system state sets. You can have conditional rules set to deny all connections of a certain type when security level is high and query the user when the security level is set to medium or low.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...