You will need sec/k9 for VPN. It could be easier with static addresses or at least one site as static. Others can be dynamic and you will be required to use a dynamic crypto map. You will be limited to your hardware (not sure of the number) but you could look into DMVPN and see if that would be a better fit for your needs.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...