hi m1c,
you can have site to site tunnel from PIX to many cisco hardware like router, pix, vpn concentrators, ISA, checkpoint etc.... depending on ur budget you can have any of these at the remote sites...
you will anyway have a router which will terminate the WAN circuit.. make sure that router has enough flash/DRAM to accomodate an IPSEC image.. in this case, you can have the IPSEC directly terminating on the router... this isnt very secure.. there can be huge broadcasts, and other unnecessary traffic which can hit ur LAN PCs.. If you want the router to do advanced security features, try buying a decent one like 2600..
If you want added security for ur LAN, have a PIX and block off all unnecessary data traffic coming to ur LAN.. have the IPSEC terminated on the PIX in this case..
hope this helps.. let us know if u need more inputs on this..
Raj