---
title: "Secure Calico component communications"
description: "Secure communications between Calico Open Source components — TLS, BGP authentication, and metric-endpoint access control."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico/latest/network-policy/comms/"
---

# Secure Calico component communications

## [📄️Configure encryption and authentication to secure Calico components](https://docs.tigera.io/calico/latest/network-policy/comms/crypto-auth.md)

[Turn on TLS authentication and encryption between Calico Open Source components using a custom certificate authority.](https://docs.tigera.io/calico/latest/network-policy/comms/crypto-auth.md)

## [📄️Schedule Typha for scaling to well-known nodes](https://docs.tigera.io/calico/latest/network-policy/comms/reduce-nodes.md)

[Configure the TCP port used by Typha in a Calico Open Source cluster to reduce datastore load on large clusters.](https://docs.tigera.io/calico/latest/network-policy/comms/reduce-nodes.md)

## [📄️Secure Calico Prometheus endpoints](https://docs.tigera.io/calico/latest/network-policy/comms/secure-metrics.md)

[Restrict access to Calico Open Source metric endpoints using network policy.](https://docs.tigera.io/calico/latest/network-policy/comms/secure-metrics.md)

## [📄️Secure BGP sessions](https://docs.tigera.io/calico/latest/network-policy/comms/secure-bgp.md)

[Configure BGP authentication passwords for Calico Open Source so attackers cannot inject false routing information.](https://docs.tigera.io/calico/latest/network-policy/comms/secure-bgp.md)
