This image shows the east-west traffic flow from the web/application to Oracle Cloud Infrastructure Object Storage and other Oracle network services in a regional hub and spoke topology that uses Check Point CloudGuard Network Security. This images shows 2 virtual cloud networks (VCNs):

East-west traffic flow from the web/application to Oracle Cloud Infrastructure Object Storage:
  1. Traffic that moves from the web/application tier to object storage is routed through the web/application subnet route table (destination 0.0.0.0/0).
  2. Traffic moves from the web/application subnet route table to the LPG for the web/application tier spoke VCN.
  3. Traffic moves from the web/application LPG to the LPG for the hub VCN (destination 0.0.0.0/0).
  4. Traffic moves from the hub LPG to the Check Point Security Gateway in the backend subnet over vNIC2.
  5. Traffic from the Check Point Security Gateway is routed through the backend subnet route table (destination Oracle Network Services).
  6. Traffic moves from the backend subnet route table to the service gateway.
  7. Traffic moves from the service gateway to Oracle Network Services such as Oracle Cloud Infrastructure Object Storage.