---
title: "Host endpoints"
description: "Protect host endpoints with Calico network policy."
product: "Calico Enterprise"
version: "3.21"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/"
---

# Host endpoints

## [📄️Host endpoints](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/overview.md)

[Secure host network interfaces.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/overview.md)

## [📄️Creating policy for basic connectivity](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/connectivity.md)

[Customize the Calico failsafe policy to protect host endpoints.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/connectivity.md)

## [📄️Creating host endpoint objects](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/objects.md)

[To protect a host interface, start by creating a host endpoint object in etcd.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/objects.md)

## [📄️Selector-based policies](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/selector.md)

[Apply ordered policies to endpoints that match specific label selectors.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/selector.md)

## [📄️Failsafe rules](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/failsafe.md)

[Avoid cutting off connectivity to hosts because of incorrect network policies.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/failsafe.md)

## [📄️Pre-DNAT policy](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/pre-dnat.md)

[Apply rules in a host endpoint policy before any DNAT.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/pre-dnat.md)

## [📄️Apply on forwarded traffic](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/forwarded.md)

[Learn the subtleties using the applyOnForward option in host endpoint policies.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/forwarded.md)

## [📄️Summary of host endpoint policies](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/summary.md)

[How different host endpoint rules affect packet flows.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/summary.md)

## [📄️Connection tracking](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/conntrack.md)

[Workaround for Linux conntrack if Calico policy is not working as it should.](https://docs.tigera.io/calico-enterprise/3.21/reference/host-endpoints/conntrack.md)
