.. it's all such a long time ago.

I dimmly remember (in 8.1.6 I think, or even 8.0.2) that if a server is configured for encryption, even if the option is "refused", then any client connecting must also be configured for encryption.
My intention is to have this type of configuration as this server itself can act like a client for other sqlnetencrypted server.
You will be obliged to set up the client-side encryption on the server - does it work if you don't? - does it work if you do?

For client & server on the same machine: Maybe IPC side-steps this? (it should - but that's opinion not fact) So perhaps that would not inccur the overhead of encryption?