Located in the distribution layer or in the data center, Aruba 6000 Mobility Controllers manage complex and processing-intensive authentication and encryption, virtual private networking (VPN), Layer 2-3 networking, Policy Enforcement Firewall (PEF), Adaptive Radio Management (ARM), and the RFProtect Spectrum Analysis and Wireless Intrusion Protection capabilities. The wireless LAN configuration is virtualized and implemented in cost-effective 802.11n access points (APs) at the access layer. APs can move user traffic to Aruba 6000 Mobility Controllers through secure IP tunnels over a public or private transport network, and locally bridge at the access layer, depending on the end user application or traffic forwarding requirements set forth by IT administrators.