1. Yup.
2. Yes that is fine. not really split tunnelling.
3. re: the no in two:
You want to get familiar with nat 1 and nat 0.
you will be using:
nat 1 0 0 0 0
or something like it (you can be more selective with it such that you only nat the ip block they use, and not everything)- this nats everything.
and a statement like:
nat 0 access-list accesslistnamehere
this disables nat for the statements in the acl names accesslistnamehere
Each pix will have a pair of nat statments, the nat 1 will enable nat for everything, and nat 0 will selectively disable it. You will need to learn to get familiar with cisco access lists.