This image shows an Oracle Cloud Infrastructure region containing three availability domains (AD), with a virtual cloud network (VCN) spanning those domains. AD 1 contains five subnets, identified as subnets A through E. ADs 2 and 3 are empty in this diagram.

The subnets are arrayed top to bottom, as follows:

External web clients access the region via an Internet Gateway while internal web clients must go through a VPN, then a dynamic routing gateway, and then into subnet D. Object storage is independent of any AD but within the VCN.

Traffic is routed from subnet D through Subnets C, B, and A. Access to each subnet layer is enforced by a security list, which is independent of any AD but within the VCN.