This image shows the traffic flow from an on-premises customer data center to an Oracle Cloud Infrastructure region through a Palo Alto Networks frewall.
At the top of the image is an on-premises customer data center. Beneath that is a primary OCI region. This region contains a Palo Alto Hub virtual cloud network (VCN) and an Application Spoke VCN.
The Palo Alto Hub VCN contains these subnets:
- An untrust private subnet. Traffic is routed between this subnet and the internet gateway via an untrust vNIC.
- A Palo Alto Management public subnet, containing to Palo Alto virtual machines (VM).
- A Palo Alto high-availability subnet.
- A trust private subnet. Traffic is routed between this subnet and the internet gateway via a trust vNIC.
- A load balancer public subnet, containing an active application load balancer and an inactive default second load balancer, which is created by OCI.
- An Oracle E-Business Suite (EBS) private subnet, containing two EBS applications and one Enterprise Command Center. The Application traffic in this subnet flows from the second EBS app to the first EBS app and is then directed to a file system astride the subnet and the region.
- An Exadata Cloud Service private subnet that contains an Exadata Cloud Service VM cluster and an associated file system.
- An Exadata Cloud Service private backup subnet.
In this scenario, traffic flows from the on-premsies customer data center through ab internet gateway to the trust private subnet in the Palo Alto Hub VCN. Traffic is then passed to the Palo Alto Management public subnet, then back to the trust private subnet, whence it flows back through the DRG to the Application Spoke VCN.