Two centralized network traffic inspection patterns for Oracle Database@AWS are detailed: one using AWS Transit Gateway with a dedicated inspection VPC for single-Region deployments, and another using AWS Cloud WAN with service insertion for multi-Region architectures. Both patterns route east-west (app-to-database) and north-south (internet outbound) traffic through a firewall inspection VPC because inline inspection cannot be deployed directly in the ODB transit VPC. Step-by-step packet walkthroughs cover each flow, and key considerations include peered CIDRs configuration, appliance mode for flow symmetry, DNS traffic handling, and multi-Region deployment strategies.
Table of contents
PrerequisitesPattern 1: Centralized traffic inspection with AWS Transit GatewayPattern 2: Centralized traffic inspection with AWS Cloud WANConsiderationsConclusionAbout the authors190 Impressions