I've never used the SME Server VPN. I've always been leary of placing the VPN tunnels on the primary site servers, and instead just used a smoothwall box with IPSec tunnels back to the primary office. In fact, I have one regional site with 20 tunnels to the main office, and the only issues I've had are with the DSL or T1 circuits, or with a hardware problem on the smoothwall boxes or the CPE units.
That said, I haven't yet configured a company that has tunnels to the main office, as well as tunnels between each location. Just like in your example, I've always had the VPN between location 1 & 2, 1 & 3, and 1 & 4. But I was thinking about a 1 to 2, 1 to 3, and a 2 to 3.
My only other experience has been with the hit and miss nature of the SME PPTP and low quality DSL circuits. Just not dependable enough.