The Proxy With Network Separation mode of the database firewall deployment requires that the originator direct requests to the database firewall. Therefore the database firewall intercepts all communications from users or applications in the external network or internal network, to the database services. The database services respond back to the originator without involving the database firewall.

The upper part of the diagram consists of two blocks. The left block has icons of Oracle Audit Vault Server, database firewall, and the switch. The Oracle Audit Vault Server and the database firewall are linked to the Switch at the bottom. The database firewall icon is then connected to the database firewall proxy source icon in the second block on the right.

The second block on the right is of the database network. It contains one icon of the database firewall proxy source which is connected to a switch. The switch is linked to one or more databases on one side and the multiple clients at the bottom.

The block at the bottom is of the client network. It consists of multiple clients. The clients connect to the database network through the network router. The router is located between the database network and the client network. It is also connected to the switch in the management network.