---
title: "Host endpoints"
description: "Reference content for protecting host endpoints with Calico Open Source network policy including failsafe ports, applyOnForward, pre-DNAT, and connectivity behavior."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico/latest/reference/host-endpoints/"
---

# Host endpoints

## [📄️Host endpoints](https://docs.tigera.io/calico/latest/reference/host-endpoints/overview.md)

[Reference overview of host endpoint protection in Calico Open Source covering the model for securing host network interfaces with policy.](https://docs.tigera.io/calico/latest/reference/host-endpoints/overview.md)

## [📄️Creating policy for basic connectivity](https://docs.tigera.io/calico/latest/reference/host-endpoints/connectivity.md)

[Reference for the Calico Open Source failsafe policy that protects host endpoints from being cut off when host network policy is misconfigured.](https://docs.tigera.io/calico/latest/reference/host-endpoints/connectivity.md)

## [📄️Creating host endpoint objects](https://docs.tigera.io/calico/latest/reference/host-endpoints/objects.md)

[Reference for the HostEndpoint object in Calico Open Source describing how to represent a host network interface so policy can select it.](https://docs.tigera.io/calico/latest/reference/host-endpoints/objects.md)

## [📄️Selector-based policies](https://docs.tigera.io/calico/latest/reference/host-endpoints/selector.md)

[Reference for ordered host endpoint policies in Calico Open Source that match interfaces using label selectors.](https://docs.tigera.io/calico/latest/reference/host-endpoints/selector.md)

## [📄️Failsafe rules](https://docs.tigera.io/calico/latest/reference/host-endpoints/failsafe.md)

[Reference for the Calico Open Source failsafe inbound and outbound port lists that prevent host network policy from cutting off control-plane connectivity.](https://docs.tigera.io/calico/latest/reference/host-endpoints/failsafe.md)

## [📄️Pre-DNAT policy](https://docs.tigera.io/calico/latest/reference/host-endpoints/pre-dnat.md)

[Reference for pre-DNAT host endpoint policy in Calico Open Source that applies rules to ingress traffic before destination NAT rewrites the address.](https://docs.tigera.io/calico/latest/reference/host-endpoints/pre-dnat.md)

## [📄️Apply on forwarded traffic](https://docs.tigera.io/calico/latest/reference/host-endpoints/forwarded.md)

[Reference for the applyOnForward field on Calico Open Source host endpoint policy that determines how rules apply to forwarded traffic versus local processes.](https://docs.tigera.io/calico/latest/reference/host-endpoints/forwarded.md)

## [📄️Summary of host endpoint policies](https://docs.tigera.io/calico/latest/reference/host-endpoints/summary.md)

[Reference summary describing how the different Calico Open Source host endpoint policy types interact and affect packet flows.](https://docs.tigera.io/calico/latest/reference/host-endpoints/summary.md)

## [📄️Connection tracking](https://docs.tigera.io/calico/latest/reference/host-endpoints/conntrack.md)

[Reference covering Linux conntrack workarounds for Calico Open Source host endpoint policy when stateful tracking interferes with expected packet flow.](https://docs.tigera.io/calico/latest/reference/host-endpoints/conntrack.md)
