Skip to main content
Question

Policy Network Segment Limitations

  • September 3, 2015
  • 4 replies
  • 17 views

Forum|alt.badge.img+7

Does anyone know for certain whether network segment limitations on policies match against the IP Address or Reported IP Address fields when evaluated?

4 replies

bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • September 6, 2015

@danf_b I think it's Reported IP Address. As this will only differ from the IP Address when a client is reporting in off WAN.


Forum|alt.badge.img+16
  • Honored Contributor
  • September 6, 2015

@bentoms wouldn't it be the opposite since the IP address would tell you when they are coming from the WAN and thus should get an external DP, etc?

If it was the reported IP which reports the clients local LAN IP address you'd never know that it was coming from outside the network.


golbiga
Forum|alt.badge.img+21
  • Employee
  • September 7, 2015

The JSS evaluates both. If you look at the logs when a machine is checking in, you will notice that its checking both IP Address and Reported IP Address to see if either fall under any of the network segments.

Allen


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • September 7, 2015

@chriscollins well of the reported differed from the IP address then the client is off-WAN.

That's what I meant.