Note: A product listed in this article has either reached hardware End of Life (EOL) OR software End of Engineering (EOE). Refer to
End of Life Products & Milestones for the EOL, EOE, and End of Support (EOS) dates.
Creating a VPN Group for a Policy-Based VPN Using NSM
To create a VPN group for a policy-based VPN using NSM, perform the following steps:
Add the devices as listed below. For more information, go to Create a Device in NSM.
- Two Main Devices
- Main-Device-1
- Main-Device-2
- Three Branch Devices
- Branch-Device1
- Branch-Device2
- Branch-Device3
The following is an example of the five configured devices:

Create Protected Resources for each of the devices. For more information, go to: NetScreen-Security Manager Administrators Guide.
Example of Protected Resource for the Main Devices:

Example of Protected Resource for Branch-Device1:

Example of Protected Resource for Branch-Device2:

Example of Protected Resource for Branch-Device3:

In the left pane, expand VPN Manager, and then click to select VPNs.

In the right pane, click the New button.

From the New menu, click AutoKey IKE VPN.

From the AutoKey IKE VPN dialog box, in the Name text box, enter a name for the VPN. Click OK.
In this example, we named the VPN AE_All.

From the left pane, expand VPNs, and then click to select the new VPN.

In the right pane, under Policy Based Configuration, click Protected Resource.

From the Protected Resource dialog box, click to select Protected Resource.
After clicking Protected Resource, the other boxes will populate as well.

Click OK.
In the right pane, under General Configuration, click Topology.

From the New Topology dialog box, under Mains, click to select the main devices. Under Branches, click to select the branch devices.

Click OK.
From the Topology dialog box, click OK.

In the right pane, click Gateway Parameters.

From the AutoKey IKE VPN dialog box, enter values for Hello Interval (sec), Reconnect, and Threshold.

Click OK.
Click Save.

In the left pane, expand Device Manager, and then click to select FW/VPN Devices.

From the FW/VPN Device Tree tab, right-click the device you want to edit, and then click Edit.

In the left pane, expand VPN Settings, and then click to select Gateway.

In the right pane, identify the VPN Gateway Name associated with both the devices.
In this example, the names are as follows:
- vpn-0@AE_All : Main-Device-1
- vpn-4@AE_All : Main-Device-2

Click OK.

In the left pane, click to select AE_All.

In the right pane, click Device Configuration.

From the AutoKey IKE VPN dialog box, in the left pane, expand Branch-Device1, and then click to select VPN Group.

In the right pane, click to select the VPN group, and then click the Edit button.

From the 1-VPN Group dialog box, edit the details as required.

Click OK.
Click Save.

In the right pane, right-click Branch-Device1, and then click to select Update Device.

Step 26 through Step 31 for all branch devices.
2020-10-18: Tagged article for EOL/EOE.