I don't even know know if this is possible with a 5 pix or a VPN Concentrator, but I believe it is if I'm understanding what I've read correctly. What I'm looking at doing is while the PIX 501 is constantly connected to the VPN Concentrator 3000, I want the users to have to authenticate themselves when attempting to connect to any IP, ec for a few select IP's and ports, on the other side of the vpn. Then require them to reauth every 15-20minutes.
As I said I believe I can do this with the aaa-server in the pix or even 2 factor authentication on the concentrator, but I'm unsure how I would configure it or if i've read everything correctly.