Hi @Martinmajestic-3285,
Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.
- You can use Azure Firewall in a hub virtual network to route and filter traffic between multiple spoke virtual network. Subnets in each of the spoke virtual networks must have a UDR pointing to the Azure Firewall as a default gateway for this scenario to work properly.
- Reference: https://learn.microsoft.com/en-us/azure/firewall/firewall-faq#can-azure-firewall-in-a-hub-virtual-network-forward-and-filter-network-traffic-between-multiple-spoke-virtual-networks
- Regarding Azure site-to-site, please follow the Microsoft document and go to the Vnet (which has a VPN Gateway) and configure VNET Peering between VNet1(which has a VPN Gateway) and VNet2 (VM).
- Please use the below screenshots for your reference:
- Also, we need to configure a static route for Vnet 2 (VM) from On-Prem server end. The static route needs to contain both VNet1(which has a VPN Gateway) and VNet2 (VM). pointing towards the same NIC.
- Please make sure that there is no IP overlapping between VNets.
If above is unclear and/or you are unsure about something add a comment below.
Please don’t forget to close the thread by clicking "Accept answer" wherever the information provided helps you, as this can be beneficial to other community members.
Thanks,
Sai.