Safeguard On Demand network doubts

Good morning,

For a configuration of Safeguard on Demand, i need to know how the VPN tunnel works. The VPN seems to have been created in one identity network, therefore is the customer that need to connect to safeguard appliance using the site to site VPN? 
If this scenario is accurate, the customer need to make the entire network available by VPN? Is possible to create a gateway and make only the gateway available by the VPN, diverting traffic internally?

And a second question, is possible to change the IP range to use in the VLAN?

Thank you,

Samuele