Kerberos GSSAPI authentication and transport encryption

Does the way MongoDB Enterprise implements Kerberos authentication via GSSAPI imply transport level encryption for the session or does TLS need to be configured on top ?

Greetings
Nils