About This Architecture
Hub-spoke network architecture on OCI with a central hub VCN (10.13.128.0/19) in us-ashburn-1 providing ingress, egress, and security controls via Internet Gateway, WAF, Network Firewall, and Load Balancer. Four spoke VCNs—App, Web, Data, and Analytics—connect through a Dynamic Routing Gateway (DRG) and Local Peering Gateways, isolating workloads while maintaining centralized routing and policy enforcement. The design implements defense-in-depth with NSGs, Security Lists, and Bastion access, while Vault/KMS secures sensitive data and ATP Database handles transactional workloads. Monitoring, Logging, Cloud Guard, and IAM policies across compartments provide visibility and governance, making this pattern ideal for regulated enterprises requiring network segmentation, cost optimization, and operational control. Fork this diagram on Diagrams.so to customize spoke VCNs, adjust CIDR ranges, or add additional security layers for your OCI deployment.