It all depends on how you want to control traffic.
You can do networks or hosts.
If you are using a pix I would suggest using object groups.
it will make your life easier to say the least.
One thing to keep in consideration in the VPN between cisco devices is the acl's need to match line for line at both ends for the tunnel. If not the tunnel will not pass phase 2