Yes, you just need to add each remote 501 network into the access-list on the other 501's and create network lists on the 3000 and define those as the local network for each L2L tunnel. If each 501 remote network is in the same major network (subnets of 10.0.0.0/8 for example), then you can just say "tunnel everything from my local network to the entire 10.0.0.0/8 network" on each PIX, and do a similar thing on the head-end 3000, makes life a lot easier.