Possibly a misuse of our naming but the old group that was used for the cluster for the VPN Domain was called ENCRYPTION_GRP so I continued the name.
The 'JAMF_ENCRYPTION_DOMAIN' includes most of our internal subnets and servers but was missing the subnet of the server I was trying to reach initially and the reason for the initial post. So I didn't mess with any production items, I copied the cluster VPN Domain group and made it the JAMF_ENCRYPTION_GRP and just added an additional two IPs (the real and NAT) of the server I was having issues with.