Off network policies - epic fail

jaferguson
New Contributor II

I have been experimenting with a policy assigned to two network
segments that are not included in our internal networks. Not
being a network guy I am not sure if these are configured
correctly but here are the network segments I configured in the
jss

Off network segment 1 -> 1.0.0.0 - 9.254.254.254
Off network segment 2 -> 11.0.0.0 - 255.255.255.255

All of our on network segments are 10.x.x.x - 10.x.x.x (too
many to enumerate here)

Both network segments are set up to use the distribution set in
our DMZ

I not only limited the policy to these network segment but also
to several departments.

The department limitation is working as expected however the
network segment limitation is not doing what I want it to do. I
only want the policy to run when the computers check in from off
our school networks.

Currently all computers (limited to the departments scope) are
running the policy without respect to where they are.

Is there anything obvious from this information that I have done
incorrectly?

Jim Ferguson
Senior Systems Analyst
Technology Services Dept.
Bryan ISD
979-209-1185

3 REPLIES 3

Not applicable

I'm new to Casper, but, I believe the following will work:

  1. Have an external DNS entry setup for your server in the DMZ.
  2. Have CNAMEs setup in the external DNS for all of your internal distribution points to point at the server above.

This should let your computers find the server when they're off campus
without you having to setup the network segma

Not applicable

I'm new to Casper, but, I believe the following will work:

  1. Have an external DNS entry created for your server in the DMZ.
  2. Have CNAMEs setup in the external DNS for all of your internal distribution points to point at the server above.

This should let your computers find the server when they're off campus
without the need to setup the network segments.

Curtis

jaferguson
New Contributor II

Clarification - > all computers with in the scope are running
the policy without respect to what network segment they are on.
Jim