Hello Tommy
Thanks for your contact
Basically, We're configuring a Site to Site VPN with a Customer.
Site to Site VPN based VTIs
Peer Remote (Customer) ------------INTERNET --------------- Peer CheckPoint on AZURE
Enviroment Azure
Peer CheckPoint on AZURE --------------ER-------------- ON-Premises
Network Remote Peer: 10.236.150.128/29
Network Peer CheckPoint on Azure: 10.236.1.0/24
Network ON Premises: 10.0.0.0/8
The flow of Traffic: Bidirectional between 10.236.150.128/29 (remote peer network) and 10.0.0.0/8 (OnPremises network)
Yes, This traffic has to go across the Express Route, We need to announce these VPNs networks so that Virtual Gateway.
Thank you so much
Everest