Would I be correct in assuming that your VPN concentrator is one of the Cisco 3000 series concentrators?
Maybe I am missing something, but it seems to me to be fairly straightforward: the concentrator specifies how to authenticate and apparently now it is configured to use its local database of user accounts. It should be a fairly simple change to specify that it should authenticate these users with Radius. At that point it should stop using local accounts.
I assume that your 3015 operates the same as the 3060s that I work with. From the Configuration line, to the User Management line, to the Groups line. Select the group that the user belongs to, on the right side of the screen is an option to modify Authentication Servers. Select this option and configure the external server that will authenticate.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...