---
title: "Policy for hosts and VMs"
description: "Use the same Calico network policy for workloads to restrict traffic between hosts and the outside world."
product: "Calico Enterprise"
version: "3.21"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/"
---

# Policy for hosts and VMs

## [📄️Protect hosts and VMs](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/protect-hosts.md)

[Create Calico Enterprise network policies to restrict traffic to/from hosts.](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/protect-hosts.md)

## [📄️Protect Kubernetes nodes](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/kubernetes-nodes.md)

[Protect Kubernetes nodes with host endpoints managed by Calico Enterprise.](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/kubernetes-nodes.md)

## [📄️Protect hosts tutorial](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/protect-hosts-tutorial.md)

[Learn how to secure incoming traffic from outside the cluster using Calico host endpoints with network policy, including allowing controlled access to specific Kubernetes services.](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/protect-hosts-tutorial.md)

## [📄️Apply policy to forwarded traffic](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/host-forwarded-traffic.md)

[Apply Calico Enterprise network policy to traffic being forward by hosts acting as routers or NAT gateways.](https://docs.tigera.io/calico-enterprise/3.21/network-policy/hosts/host-forwarded-traffic.md)
