Secure Transport : Data plane
  
Data plane
Each SteelHead in the group takes part in the data plane and secures traffic over any path marked as securable. The SteelHeads use the encryption keys received from the controller to perform encryption and use the path selection services policy received from the SCC to determine which traffic is encrypted.
Remember that the control plane is providing network reachability information related to the site such as the public IP address for a secured path.
Secure transport provides encryption services for only IPv4. IPv6 is not encrypted.
Figure: Secure transport functionality shows another view of the functionality of the management, control, and data plane for secure transport. The SCC performing the management plane is the central point for configuration of the secure transport group. The SCC passes the group configuration information to the controller and group members. The controller generates encryption key information and network-reachability information, and it also performs registration and validation of group members in the control plane.
Secure transport functionality