To simplify policy enforcement,the Aruba 500 Series uses Aruba's policy enforcement firewall (PEF) feature to encapsulate all traffic from the AP to the Mobility Controller (or Gateway) for end-to-end encryption and inspection. Policies are applied based on user role,device type,applications,and location. This reduces the manual configuration of SSIDs,VLANs and ACLs. PEF also serves as the underlying technology for Aruba Dynamic Segmentation.