All skills
acedergren avatar

/networking-management

@69c2982

Use when the user asks to "design OCI networking", "debug VCN connectivity", "configure Service Gateway", "choose NSG vs security list", or "plan FastConnect or VPN".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/networking-management

This session only. Nothing lands on disk.

referencesoci-networking-reference.md

≈796 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Networking Reference

Last verified: 2026-09-30 against docs.oracle.com and OCI CLI 3.94.1. Limits and prices change; re-check the linked pages before quoting.

Verified facts

Topic Fact
Subnet reserved IPs 3 per subnet: the first two and the last address of the CIDR
VCN CIDR size /16 to /30 per CIDR block; CIDRs can be added or modified later with restrictions
Security lists Max 5 per subnet; rules are stateful by default, stateless is opt-in per rule
NSGs A VNIC can belong to at most 5 NSGs; NSG rules can reference another NSG as source/destination
Load balancer IPs Public LB uses 2 private IPs; private LB uses 3 (primary, standby, floating). One regional subnet is recommended
Service Gateway Targets the "All <region> Services in Oracle Services Network" or "OCI <region> Object Storage" CIDR label; reaches Oracle public endpoints without an internet gateway
Peering LPG/RPC peering is not transitive; transit routing uses DRG route tables and import distributions
Pricing (price list, 2026-09-30) No charge SKUs exist for NAT gateway, DRG, or Site-to-Site VPN; FastConnect billed per port-hour (1 Gbps $0.2125, SKU B88325) with no data charges on private virtual circuits; first 10 TB/month outbound data free in most regions

Connectivity debug checklist

A packet must be allowed by every layer. Check in this order and record which layer fails:

  1. Route table of the source subnet has a rule for the destination (IGW, NAT, SGW, DRG, LPG, private IP).
  2. Security lists on both subnets (ingress on the destination, egress on the source; stateless rules need both directions).
  3. NSGs on both VNICs.
  4. ZPR policy, if the resource has security attributes (see ../zpr-security).
  5. OS firewall on the instance (firewalld/iptables on Oracle Linux images is on by default).
  6. DNS: VCN resolver, private views, and on-prem forwarding rules.

Useful commands:

oci network route-table get --rt-id "$RT_ID"
oci network security-list get --security-list-id "$SL_ID"
oci network nsg rules list --nsg-id "$NSG_ID" --all
oci network service list --all          # Service Gateway CIDR labels
oci network drg-route-table list --drg-id "$DRG_ID" --all

Network Path Analyzer (console: Networking > Network Command Center) can evaluate a path end to end.

Official Oracle Sources

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill serves as a knowledge base and command reference for Oracle Cloud Infrastructure (OCI) networking. While the content is primarily architectural guidance and CLI templates, it lacks boundary markers for user-provided variables, creating a minor surface for indirect prompt injection.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 69c2982. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 hours ago.

Activeupdated yesterday
version
2.0.0
aliases
[
  "oci-networking",
  "vcn-management"
]
domains
[
  "oci",
  "networking"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "VCN",
  "subnet",
  "NSG",
  "security list",
  "Service Gateway",
  "DRG",
  "FastConnect",
  "VPN",
  "Terraform",
  "route table",
  "private endpoint",
  "DNS resolver",
  "NAT Gateway",
  "ZPR",
  "OCI Bastion"
]

README badge

README badge for acedergren/agentic-tools/networking-management