---
title: "Policy for extreme traffic"
description: "Apply Calico Open Source network policy early in the Linux packet-processing pipeline to handle DoS, high-connection, and other extreme traffic scenarios."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/"
---

# Policy for extreme traffic

## [📄️Enable extreme high-connection workloads](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/high-connection-workloads.md)

[Bypass Linux conntrack with a Calico Open Source policy rule for workloads that handle an extreme number of concurrent connections.](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/high-connection-workloads.md)

## [📄️Defend against DoS attacks](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/defend-dos-attack.md)

[Define DoS mitigation rules in Calico Open Source policy that drop connections at the eBPF or XDP layer, with hardware offload when available.](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/defend-dos-attack.md)
