An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Your understanding aligns with Microsoft's documented hybrid-routing design.
Place a UDR on the GatewaySubnet with the Azure Firewall/NVA as the next hop for spoke prefixes. This routes traffic arriving from on-premises through the VPN gateway to Azure workloads via the firewall.
For the opposite direction, place the appropriate UDR on the spoke/workload subnet, pointing traffic toward the firewall. The firewall then forwards the on-premises-bound traffic toward the VPN gateway.
So the documented symmetric inspection pattern is:
On-prem → VPN Gateway → Firewall → Spoke
and
Spoke → Firewall → VPN Gateway → On-prem
The first direction uses the GatewaySubnet UDR for the Azure/spoke destination, while the reverse direction requires routing on the workload/spoke side to send traffic through the firewall.
Route tables define how traffic initiated in a subnet is routed, and the documented NVA/VPN Gateway scenario uses a GatewaySubnet route specifically for traffic coming from on-premises toward Azure.
I cannot find verified Microsoft documentation stating that a VPN Gateway performs a second lookup against the GatewaySubnet UDR for packets it receives from the VNet side immediately before encapsulating them into the VPN tunnel.
Therefore, don't rely on the GatewaySubnet UDR to provide the reverse-direction inspection path. Configure the workload/spoke routing explicitly, as shown in Microsoft's documented hybrid Azure Firewall architecture.
References:
Hybrid connection with NVA and VPN Gateway
Azure virtual network traffic routing
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.