Allows the same kind of segmentation we can get in an EC2 instance (security groups, acl and so on) but in end user stations