You can also use StartTLS over the network and LDAPI (connection over Unix sockets, which are inherently secure) for apps running on the server. I use it, both with OpenLDAP and 389 Directory Server (a.k.a. Fedora DS, Red Hat DS).
Unfortunately, I have a whole LAN whose user/group/auth management is centralized with LDAP (each server having different apps). So I need plain LDAP access on the LAN.