---
title: "Get started with policy"
description: "Pick a learning path for Calico Enterprise policy — start with Kubernetes-native NetworkPolicy basics or jump to the richer enterprise resources that build on top."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/"
---

# Get started with policy

## [📄️What is network policy?](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-network-policy.md)

[Concepts you need before writing Calico Enterprise policy — how Kubernetes NetworkPolicy, Calico policy, and tiers interact.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-network-policy.md)

## [📄️Get started with Kubernetes network policy](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-network-policy.md)

[Reference for Kubernetes NetworkPolicy syntax, rules, and features when used with the Calico Enterprise enforcement engine.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-network-policy.md)

## [📄️Kubernetes policy, demo](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-demo.md)

[Interactive demo for a Calico Enterprise cluster that visualizes how Kubernetes NetworkPolicy allows and denies connections between pods.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-demo.md)

## [📄️Kubernetes policy, basic tutorial](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-policy-basic.md)

[Apply your first Kubernetes NetworkPolicy in a Calico Enterprise cluster to restrict ingress and egress traffic to and from pods.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-policy-basic.md)

## [📄️Kubernetes policy, advanced tutorial](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-policy-advanced.md)

[Write more advanced Kubernetes NetworkPolicy resources in a Calico Enterprise cluster — namespace scoping, allow-all, and deny-all variants.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/kubernetes-policy-advanced.md)

## [📄️Kubernetes services](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-kubernetes-services.md)

[How the three Kubernetes Service types behave in a Calico Enterprise cluster and where each one shows up in policy.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-kubernetes-services.md)

## [📄️Kubernetes ingress](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-kubernetes-ingress.md)

[How different Kubernetes ingress implementations interact with Calico Enterprise network policy at the cluster edge.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-kubernetes-ingress.md)

## [📄️Kubernetes egress](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-kubernetes-egress.md)

[Why egress traffic from Kubernetes workloads matters and how to restrict it with Calico Enterprise policy.](https://docs.tigera.io/calico-enterprise/latest/network-policy/get-started/about-kubernetes-egress.md)
