NSM: Cannot manage a device through a VPN
NetScreen-Security Manager NSM Server behind a NetScreen in a VPN NSM Client on one side of a VPN NSM Client behind a NetScreen Device uses untrust IP address to communicate to NSM
If a device is behind a NetScreen, and is trying to communicate to a NSM server that's behind another NetScreen, you'll need to configure the device to communicate to the NSM server through a VPN tunnel. To do this, you'll need to apply the command on the device:
set nsm server primary w.x.y.z src-interface <if_name>
where w.x.y.z is the NSM server internal IP address, and if_name represents the interface that the NSM client is behind.