if you have watchguard at the satellite office you could certainly set it up there the same as at the home office. With so few users you could also put phones on 192.168.200.0 network.
Whatever you have at the satellite office will have to route traffic for the 10.0.0.0 network over the vpn tunnel along with the 192.168.100.0 traffic. If you use the same network for phones as for users at the satellite office, no additional routing will have to be set up at the home office site, if you set satellite up on a watchguard dmz interface at satellite office then you will need a routing statement in the home office to direct that new 10.x.x.x network over your vpn tunnel.
I think you are getting close