Array-based: Encryption techniques aimed at securing replication traffic is entirely dependent on what the specific storage solution or what a 3rd party WAN solution can provide.
vSphere Replication (VR): Data can be protected in-transit using built-in network traffic encryption. The VR appliance automatically installs an encryption agent on the source ESXi hosts. When the network encryption feature is enabled, the agent encrypts the replication data on the source ESXi host and sends it to the VR appliance on the recovery site. The VR server on the recovery site decrypts the data and sends it to the target datastore.
Replication and protection of Encrypted VMs is also supported when using VMware vSphere 6.7 Update 1 or later. When protecting an encrypted VM, network encryption is automatically turned on and cannot be disabled.