---
title: "Policy for hosts and VMs"
description: "Apply Calico Open Source network policy to host interfaces — extending the same selector-based policy model from pods to bare-metal hosts and VMs."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "Network policy"
canonical_url: "https://docs.tigera.io/calico/latest/network-policy/hosts/"
---

# Policy for hosts and VMs

## [📄️Protect hosts and VMs](https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts.md)

[Protect Kubernetes hosts and bare-metal nodes with Calico Open Source policy by writing rules that target host endpoints.](https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts.md)

## [📄️Protect Kubernetes nodes](https://docs.tigera.io/calico/latest/network-policy/hosts/kubernetes-nodes.md)

[Protect Kubernetes node interfaces with Calico Open Source host endpoints to extend network policy to the node itself.](https://docs.tigera.io/calico/latest/network-policy/hosts/kubernetes-nodes.md)

## [📄️Protect hosts tutorial](https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts-tutorial.md)

[Tutorial for protecting hosts in a Calico Open Source cluster — register host endpoints, write rules, and allow controlled access to specific Kubernetes services.](https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts-tutorial.md)

## [📄️Apply policy to forwarded traffic](https://docs.tigera.io/calico/latest/network-policy/hosts/host-forwarded-traffic.md)

[Apply Calico Open Source network policy to traffic forwarded through hosts acting as routers or NAT gateways.](https://docs.tigera.io/calico/latest/network-policy/hosts/host-forwarded-traffic.md)
