The image depicts the flow of DMZ web service exposed to the internet. The application load balancer is on a public subnet and the backend servers are in private subnets of spoke VCN.

The image shows an OCI Region that includes two VCNs and an Oracle Services Network containing OCI Object Storage.

The first VCN contains these public subnets:

The first VCN connects to the internet via NAT gateway and internet gateway, Oracle Services Network via service gateway and on-premises setup with VCN Attachement RT via DRG using FastConnect and Site-to-Site VPN.

The second VCN contains these subnets:

The second VPN connects to the on-premises setup via DRG using FastConnect and Site-to-Site VPN.

The detailed flow on each hop is described in the text following the image.