A quick setup is the following
* Run crossover cable between the routers by using one of the unused ports of each router
* Configure a new VLAN on each router
* This new VLAN will be your DMZ or secondary Outside from security zone perspective
* Terminate the IPSec VPN tunnel using this new VLAN
* You can use any IP address as the IPSec VPN tunnel termination (including Private IP addresses) as long as they are valid IP version 4 addresses
With such setup, you don't disturb your Internet or production network during implementation and troubleshooting.
Following is some guideline of setting up Site-to-Site IPSec VPN. As a start, it shows some sample configuration using PIX Firewall but then it continues to show various sample configurations using routers, VPN Concentrator, and some non-Cisco equipment.
»Cisco Forum FAQ
»Various Site-to-Site IPSec VPN: Cisco, Juniper, Checkpoint, Sonicwall, Zywall
Go through all sample configurations and read those documents in Phases 1 and 2, and then you should get a better understanding and ideas to start