If it is just the one machine at each end, just make each the default DMZ machine for the router (seems to be the name of the option on my router anyway), then use the firewall on each machines to only allow the ip address of the other router to connect, then just give them an entry in /etc/hosts on the opposite machine, then simply treat them as normal.
Or, if you only want authentication, just open the relevant port, probably better than the above.
Of course the above method is really insecure, hackable in minutes perhaps, but still, easier than VPN.
Also, not sure if /etc/hosts is right for macs, works in linux anyway.
Some VPN systems support openssl encryption with good key strength, if the routers provide something, use that, otherwise try openVPN on the machines themselves
Rereading what you said and what I just wrote, most of what I wrote is useless to you, posting it anyway incase it helps.
ico2