I've been asked to do a lot of (stupid/impossible/whatever) things in my IT career, but I've never been asked to configure a VPN with no administrative access to the device on my end of the connection. What. A. Nightmare.
You need console access, period. Only then can a process be developed that might, I repeat might, be plug and play in other locations. And it's wasted effort if it's not documented.
$0.02
As for running two firewalls, it's not necessarily a problem, it's one way to slowly turn up a NGFW, while keeping the traditional IPs and Ports firewall in place.