Policy for extreme traffic

Use Calico network policy early in the Linux packet processing pipeline to handle extreme traffic scenarios.

Enable extreme high-connection workloads

Create a Calico network policy rule to bypass Linux conntrack for traffic to workloads that experience extremely large number of connections.

Defend against DoS attacks

Define DoS mitigation rules in Calico policy to quickly drop connections when under attack. Learn how rules will use eBPF and XDP, including hardware offload when available.