Modes of operation
You can configure IPsec on Red Hat OpenShift Container Platform clusters in Disabled, External, or Full pod-to-pod and external encryption modes. Each mode determines which traffic OVN-Kubernetes encrypts by default.
The following table describes the different modes of operation:
| Mode | Description | Default |
|---|---|---|
|
No traffic is encrypted. This is the cluster default. |
Yes |
|
Pod-to-pod traffic is encrypted as described in "Types of network traffic flows encrypted by pod-to-pod IPsec". Traffic to external nodes may be encrypted after you complete the required configuration steps for IPsec. |
No |
|
Traffic to external nodes may be encrypted after you complete the required configuration steps for IPsec. |
No |