---
title: "Host endpoints"
description: "Reference content for protecting host endpoints with Calico Cloud network policy across connected clusters including failsafe ports, applyOnForward, and pre-DNAT."
product: "Calico Cloud"
version: "v23.0.1"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico-cloud/reference/host-endpoints/"
---

# Host endpoints

## [📄️Host endpoints](https://docs.tigera.io/calico-cloud/reference/host-endpoints/overview.md)

[Reference overview of host endpoint protection in Calico Cloud covering the model for securing host network interfaces with policy across connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/overview.md)

## [📄️Creating policy for basic connectivity](https://docs.tigera.io/calico-cloud/reference/host-endpoints/connectivity.md)

[Reference for the Calico Cloud failsafe policy that protects host endpoints in connected clusters from being cut off by misconfigured host policy.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/connectivity.md)

## [📄️Creating host endpoint objects](https://docs.tigera.io/calico-cloud/reference/host-endpoints/objects.md)

[Reference for the HostEndpoint object in Calico Cloud describing how to model a host network interface in a connected cluster so policy can select it.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/objects.md)

## [📄️Selector-based policies](https://docs.tigera.io/calico-cloud/reference/host-endpoints/selector.md)

[Reference for ordered host endpoint policies in Calico Cloud connected clusters that match interfaces using label selectors.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/selector.md)

## [📄️Failsafe rules](https://docs.tigera.io/calico-cloud/reference/host-endpoints/failsafe.md)

[Reference for the Calico Cloud failsafe inbound and outbound port lists that prevent host network policy from cutting off control-plane connectivity.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/failsafe.md)

## [📄️Pre-DNAT policy](https://docs.tigera.io/calico-cloud/reference/host-endpoints/pre-dnat.md)

[Reference for pre-DNAT host endpoint policy in Calico Cloud connected clusters that applies rules to ingress traffic before destination NAT rewrites the address.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/pre-dnat.md)

## [📄️Apply on forwarded traffic](https://docs.tigera.io/calico-cloud/reference/host-endpoints/forwarded.md)

[Reference for the applyOnForward field on Calico Cloud host endpoint policy that controls how rules apply to forwarded traffic in connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/forwarded.md)

## [📄️Summary of host endpoint policies](https://docs.tigera.io/calico-cloud/reference/host-endpoints/summary.md)

[Reference summary describing how the different Calico Cloud host endpoint policy types interact and affect packet flows in connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/summary.md)

## [📄️Connection tracking](https://docs.tigera.io/calico-cloud/reference/host-endpoints/conntrack.md)

[Reference covering Linux conntrack workarounds for Calico Cloud host endpoint policy when stateful tracking interferes with packet flow in connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/conntrack.md)
