Dan,
No VPN routers required. That's the beauty of this feature. Every IP set produced by Nortel has had a VPN client termination built into it and the NAT traversal license allows it to be used by the BCM directly without any intervention from us. Only the box checked off under the IP set parameters. It makes the phone portable too. All you usually need is an internet connection and power of course.
Given how this is working for you at the moment, I would suspect a default gateway is set improperly somewhere. Whenever you get one-way or no-way audio, it's a network issue. Once the set is registered to the BCM, the packets will flow directly from set to set if they are both IP, but from the BCM to the set if one of the sets is digital or it is a trunk call. So, if there is no audio, it's generally because the voice packets that are using ports 28000-28255 can't find a path to the ip set.
Unfortunately that means dealing with the network guys to figure out what default gateway needs to be assigned to which device. Could also be a vlan issue but that's another story.
How do you connect to the other building? Are there separate internet connections to each site?