In general, you want the encryption as close to the client as possible. Some clients will dial up over a telephone line to a public inetrnet acces spoint, and then run VPN (like the CISCO VPM client) over that. Sounds like this is the way you are wanting to go.