A site-to-site VPN connects two networks through their edge routers or firewalls. You configure a tunnel between the devices, and all traffic matching certain criteria flows through it automatically.
Employees at either site don't need VPN software. Their traffic enters the tunnel transparently. If your headquarters uses and your branch uses , packets between these ranges traverse the encrypted tunnel. Everything else goes directly to the internet.