Each network segment should have it's own nessus server. You'll get into serious trouble with routers (routing tables filling up) and firewalls (blocked ports) otherwise. Chapter 2 pp 35-37 in [B1] describes the best policy for placing servers. How to use nessus depends on what kind of machines is on a given network segment. Chapter 10 in [B1] goes into great detail as to how one should implement a policy. You'ld use one scanning policy for the servers and another for the workstations. The authors recommend a daily scan and iomplementing a policy for each kind of server.