The image depicts the flow of traffic between on-premises and OCI. To understand the flow of traffic between spokes in OCI, we can consider on-premises as one of the spokes. In that case the only change is the route table referred on the spoke attachment. This deployment can be referred to single arm mode, where the traffic will enter and leave the same interface of the firewall, here the interface is the trust interface.
The image shows an OCI Region that includes two VCNs and an Oracle Services Network containing OCI Object Storage.
The first VCN connects to the internet via NAT gateway and internet gateway, Oracle Services Network via service gateway and on-premises setup with VCN Attachement RT via DRG using FastConnect and Site-to-Site VPN.
The second VPN connects to the on-premises setup via DRG using FastConnect and Site-to-Site VPN.
The detailed flow on each hop is described in the text following the image.