IF the remote site has a static IPv4 address, then you could also try using 6to4 address space (2002::/16)
You can use an online calculator to figure out your 2002:xxxx:yyyy::/48 prefix based on your IPv4 address
open the IPv4 to IPv6 transitional tool
type your IP address into Customer IPv4 and leave the "using" value set to 32.
Click the ISP->Customer buton.
e.g.: 192.0.2.32 -> 2002:a0b:1621::/48
You may then use any /64 prefixes from this block that you like as the LAN interface addresses.
You'd want to put two tunnel interfaces to make this work well:
one is designed with the remote IPv4 address of the main site with "real" IPv6 addresses - build the tunnel as I explained earlier, but route your 6to4 /48 block across it at the main site (to avoid using a public 6to4 relay when communicating site to site)
On the 6to4 site, you'll want to static route to your main site's block across the site-to-site tunnel.
The other tunnel interface will need remote IP set to 184.108.40.206, and you'll want your IPv6 default gateway to be 2002:C058:6301::1
This will be the "wan" interface of your remote site's router as far as IPv6 goes, and that's where you want to put your filter rules to block new incoming connections by default.
Oh - one last thing - the IPv4 firewall's input chain will need to accept protocol 41 (where you normally put tcp or udp, put 41) - this is the 6in4 tunnel protocol number.