I tried the settings that PacketTracer suggested. No success unfortunately - with those in effect, regardless of whether IPv6 Simple Security is enabled or disabled, all IPv6 traffic appears to be blocked in both directions. In the router logs under Router Status, I get entries like this:
Drop TCP packet (src: (my IP address) /48112, dst:2a03:2880:0020:8f08:face:b00c:0000:0001/80) by firewall rule(s).
Clearly this firewall rule should be allowing this packet to go through, so it seems like the rules are simply not being applied properly in this version of the firmware.