About This Architecture
Hub-and-spoke network security architecture on OCI centralizes inbound traffic through WAF and Network Firewall before routing to four specialized spoke VCNs: Web, App, Data, and Analytics. Internet users connect via OCI WAF and Layer 7 Load Balancer to the Hub VCN's Network Firewall, which enforces security policies and routes traffic through a Dynamic Routing Gateway to spoke workloads. This topology isolates workload tiers—compute instances in Web and App spokes, Autonomous Database in Data spoke, Big Data Service in Analytics spoke—while maintaining centralized security controls and reducing blast radius. Fork this diagram on Diagrams.so to customize compartment boundaries, add additional spokes, or integrate FastConnect for hybrid connectivity. The DRG acts as the central routing hub, enabling controlled inter-spoke communication while Network Firewall provides stateful inspection of all north-south traffic.