You can install vpn concentrator 3005 series at each site and run a lan to lan tunnel between each spoke site and your hub site. For added security you can
install pix firewalls infront of the vpn conentrator, to insure that only the *right* source even can attempt a tunnel to your vpn network.