Hi Stella
You can think off going on for a Dynamic IPSEC VPN scenario.
In this case all your remote clients (workstations) with VPN Client software installed can get onto your HO router and get an ip address issued by the HO router.
Once the same is done you can access the internal HO Lan from the remote location workstations.
About hardware design at the HO end it all depends upon how many concurrent VPN sessions will be established from the remote clients.
Once the same is available you can opt for a model on your own referring the data sheets of the models available out here in CCO.
you can also refer this which will be helpful in understanding the same..
http://www.cisco.com/en/US/products/sw/iosswrel/ps1839/products_feature_guide09186a008055c37a.html
regds