This image shows the east-west traffic flow from the web/application to Oracle Cloud Infrastructure Object Storage and other Oracle Services Network in a regional hub and spoke topology that uses Palo Alto Networks VM-Series Firewall.

It includes two virtual cloud networks (VCNs):

East-west traffic flow from the web or application to Oracle Cloud Infrastructure Object Storage:

  1. Traffic that moves from the web or application tier to object storage is routed through the web or application subnet route table (destination 0.0.0.0/0).
  2. Traffic moves from the web or application subnet route table to the LPG for the web or application tier spoke VCN.
  3. Traffic moves from the web or application LPG to the LPG for the hub VCN (destination 0.0.0.0/0).
  4. Traffic moves from the hub LPG to the Palo Alto Networks VM Series Firewall in the trust subnet over vNIC2.
  5. Traffic from the Palo Alto Networks VM series firewall is routed through the trust subnet route table (destination Oracle Network Services).
  6. Traffic moves from the trust subnet route table to the service gateway.
  7. Traffic moves from the service gateway to Oracle Services Network, such as Oracle Cloud Infrastructure Object Storage.