Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I understand that you would like to use Azure Firewall as NVA for traffic to and fro OnPrem via ExpressRoute.
From your verbatim,
- Azure to OnPrem traffic passes via the Firewall
- However, OnPrem to Azure traffic does not
- Ideally, defining the Address space of the SpokeVNETs and nextHop as the Firewall's private IP should do the trick
- See a similar set up here
- Can you confirm Propagate gateway routes is set to "Enabled"?
- May I ask if you are testing this by initiating traffic from OnPrem to the Azure?
- Or you are worried that you are not seeing return traffic for Azure to OnPrem testing
- Can you specify if you are using ExpressRoute FastPath?
Cheers,
Kapil