---
title: "Host endpoints"
description: "Reference content for protecting host endpoints with Calico Enterprise network policy including failsafe ports, applyOnForward, pre-DNAT, and connectivity behavior."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/"
---

# Host endpoints

## [📄️Host endpoints](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/overview.md)

[Reference overview of host endpoint protection in Calico Enterprise covering the model for securing host network interfaces with policy.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/overview.md)

## [📄️Creating policy for basic connectivity](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/connectivity.md)

[Reference for the Calico Enterprise failsafe policy that protects host endpoints from being cut off when host network policy is misconfigured.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/connectivity.md)

## [📄️Creating host endpoint objects](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/objects.md)

[Reference for the HostEndpoint object in Calico Enterprise describing how to model a host network interface so policy can select it.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/objects.md)

## [📄️Selector-based policies](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/selector.md)

[Reference for ordered host endpoint policies in Calico Enterprise that match interfaces using label selectors.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/selector.md)

## [📄️Failsafe rules](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/failsafe.md)

[Reference for the Calico Enterprise failsafe inbound and outbound port lists that prevent host network policy from cutting off control-plane connectivity.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/failsafe.md)

## [📄️Pre-DNAT policy](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/pre-dnat.md)

[Reference for pre-DNAT host endpoint policy in Calico Enterprise that applies rules to ingress traffic before destination NAT rewrites the address.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/pre-dnat.md)

## [📄️Apply on forwarded traffic](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/forwarded.md)

[Reference for the applyOnForward field on Calico Enterprise host endpoint policy that controls how rules apply to forwarded traffic.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/forwarded.md)

## [📄️Summary of host endpoint policies](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/summary.md)

[Reference summary describing how the different Calico Enterprise host endpoint policy types interact and affect packet flows.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/summary.md)

## [📄️Connection tracking](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/conntrack.md)

[Reference covering Linux conntrack workarounds for Calico Enterprise host endpoint policy when stateful tracking interferes with packet flow.](https://docs.tigera.io/calico-enterprise/latest/reference/host-endpoints/conntrack.md)
