
This article applies to ScreenOS 5.0 and 4.0.
To configure VPN modifications for the NetScreen device, perform the following steps:

Open the
WebUI. For more information on accessing the WebUI, select your product from the list below:

From the NetScreen options menu, click
VPNs, select
AutoKey Advanced, and then click
Gateway.


From the
Gateway screen, click
Edit to modify your preconfigured
Gateway.
![]()
In this example, we are modifying the Gateway for a dial up VPN. For information on how to configure a dial up VPN using pre-shared keys, go to
Configuring a Dial Up VPN Using Pre-shared Keys.


Click
Advanced.


From
Security Level User Defined, click to select
Custom.


In the
Phase 1 Proposal drop-down menu, click to select the
Phase 1 Proposal that corresponds to the certificate type created.

From the
Preferred Certificate Local Cert drop-down menu, click to select the local certificate for this device.

Choose this option when multiple certificates have been loaded on the device. Additionally, the Administrator can specify the preferred Peer CA and Peer Type (X509 or PKCS7) for this VPN connection.


Click
Return.


Click
OK.


From the NetScreen options menu, click
Objects, select
Users, and then click
Local.


From the
Local screen, click
Edit to modify your preconfigured Local User.


In the
IKE Identity text box, enter the
IKE Identity to match the NetScreen-Remote Client.


Click
OK.


This is how the Local User will now appear.


Now you are ready to configure VPN modifications for the NetScreen device. For more information, go to
Configuring VPN Modifications for the NetScreen-Remote Client.