Yes, you need to port forward UDP 500 at the static IP end to the UTM WAN IP, as I assume the SMC's is performing full NAT
1. Yes, simply point the dynamic end at the head office static IP with the port forward mentioned above
2. specify the remote and local ID's using an @ symbol...as per the user manual
3. yes, if you use ID's as mentioned above
Knowledge base article KB62286 may assist, but the user manaul should have all you need.