Hi @Rachit R , I understand you're using APIM - Developer SKU (classic). You have a requirement to limit inbound access to APIM to private only. You have configured APIM with internal vnet injection (classic tier).
Your question is about outbound path to internet. Answer: you need to provide outbound path, which could be a Firewall (seems you've chosen this one) or a NAT Gateway.
More info:
- Deploy and configure Azure Firewall and policy using the Azure portal
- Create a NAT gateway using the Azure portal
Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.