You can configure a simple PIX to PIX VPN. Do you have hosts on the public network that would want to access Internal resources? If there is no access from outside and only users from inside have to access the internet, I don't see a need for the VPN. The sample config can be found at:
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...