I use LAN1 into a router, the IT person provides me a dedicated tunnel to all the sites. Each site has a gateway address, plus their own network addresses for each site.
Example gateway and IPO
192.168.3.1 and 3.10, VM pro pc 3.20
192.167.5.1 and 5.10
192.168.6.1 and 6.3
Each site needs to be able to ping each site and all ports should be opened up on the dedicated tunnels.
Manager at each location should be able to see all sites.