Hi,
When you create a S2S IPsec VPN, all IP traffic is by default permitted to flow between both sites (networks defined as interesting traffic).
You can create the ACL to permit only the IPs and ports neccesary (but depending on the size of the scenario could be a long or complex ACL).
There are other features that enhance security, for example:
Users can be required to authenticate before accessing any resources on your LAN.
This can be done with an external Radius server.
Besides authentication, authorization can be implemented so that users are validated and only allowed certain permissions.
A lot depends on what you have and can/cannot do.
Hope it helps.
Federico.