---
title: "Application layer policies to control ingress traffic"
description: "Restrict ingress traffic to Calico Enterprise workloads by HTTP method, path, or other Layer-7 attributes using application-layer policy."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/network-policy/application-layer-policies/"
---

# Application layer policies to control ingress traffic

## [📄️Enable and enforce application layer policies](https://docs.tigera.io/calico-enterprise/latest/network-policy/application-layer-policies/alp.md)

[Configure access controls based on Layer-7 attributes by enforcing Calico Enterprise application-layer policy in the cluster.](https://docs.tigera.io/calico-enterprise/latest/network-policy/application-layer-policies/alp.md)

## [📄️Application layer policy tutorial](https://docs.tigera.io/calico-enterprise/latest/network-policy/application-layer-policies/alp-tutorial.md)

[Step-by-step tutorial for applying Calico Enterprise application-layer policy to workloads — control ingress traffic by HTTP attributes.](https://docs.tigera.io/calico-enterprise/latest/network-policy/application-layer-policies/alp-tutorial.md)
