One solutions is to have a proxy server at the central site where your remote users at the other sides use it as a proxy for their browser (or any applications) to access the Internet. The proxy server has to have routes to the remote networks at the other side of the tunnel, so it can replying back the to the clients it serves for.
Regards,
Engel