At the moment Berkeley replication API supports only TCP/IP protocol to transfer replication data between Master and Replicas.
As result, the replicated data is unprotected and can be intercepted by anyone having access to the replication network.
Also, anyone who can access to this network can introduce a new node and therefore receive a copy of the data.
In order to reduce the security risks the entire HA cluster is recommended to run in a separate network protected from general access.
Apache Qpid, Messaging built on AMQP; Copyright © 2015 The Apache Software Foundation; Licensed under the Apache License, Version 2.0; Apache Qpid, Qpid, Qpid Proton, Proton, Apache, the Apache feather logo, and the Apache Qpid project logo are trademarks of The Apache Software Foundation; All other marks mentioned may be trademarks or registered trademarks of their respective owners