My first thought was an MTU issue, but I'm not completely convinced of that yet.

What happens if you try from another machine so we can rule out the software aspect of it?

What addresses ranges do you have?

You need the % because that identifies the interface. 

Why are you converting the IPv4 to IPv6? 

If you're not able to reach the gateway, I think you've found your issue

Are you able to ping the gateway?  Can you get on the gateway and try to ping external?

So my router gives out this subnet and clients should generate any address beginning with "2001:470:1f0b:160d:", correct?

That's correct.

My firewall has 2001:470:1f0b:160d::1.  But every client has an address with prefix 2001:470:1f0c:160d:: (there is a "c" in the third group, not a "b"). Why? Am I even "allowed" to use that prefix since Tunnelbroker does not provide this one to me?

This has to be a misconfiguration on your router.  As you pointed out, this isn't one of your ranges, but since you're getting addresses in that range and your router is the one handing out addresses, your router has to be wrong.  Check for a typo in the config, or if you want, post a screenshot.

The  FE80 address is expected; it should be the local address of your gateway.  How are you handing out addresses? SLACC? DHCPv6?

Obfuscating makes it hard to help and is not needed, can you please post the real ranges?

With that being said, you're supposed to use the routed /64 for hosts behind your firewall.  If you have multiple subnets, you need to request a /48.

The outside interface of your router has an ip from your tunnel /64 and the inside interface has an IP from the routed /64

Someone else had a post on here that dealt with their inability to connect to Windows Update while using IPv6.  I didn't look for it, but it shouldn't be too hard to find.  You may find the solution to your problem in there (I don't remember the outcome of the post)

The tunnel wasn't created because HE was unable to ping your IPv4 address.  Can you confirm that the 66.x address was actually assigned to you and not to a large CGN?

2002 is 6to4, not 6in4, so that's probably why it won't work

If it were mine, I would disable what you have on the router and pass it through to something else

You can at least try it and see if your router is passing protocol 41 traffic

The second code snip you used was better because you used your nat address.

You should delete both tunnels and try again, only make it ip6tunnel

Did you hear back?

Please post:

Commands to create tunnel
Output of ipconfig

