You can use dhcp with the vpn and setup an address pool just for them so they can be on a different subnet if you want. It will also use internal dns and can be authenicated by your NT servers. Works perfect in win2000 or xp. The encryption makes no noticeable difference. The learning curve is not bad espcially since you can call cisco tech support and they will pretty well walk you through the whole setup. Documentation is great also. The concentrators also have SSL VPN now so you can use that additionally if you dont want to deploy the client portion to remote users. With ssl you can access files on your network, email, run applications and all from an internet browser. Cool stuff - that means you could be anywhere and jump on someones computer and pull files from your network. Very secure. Cisco is probably one of the best in security.
I have another web demo today with Steve Mogul at Positive Networks. He would be glad to do one for you. His number is 614-855-8490.