Hello,
Gateway R80.40
I am setting up route based (VTI) site to site VPN tunnel between on-premise and Azure. VPN tunnel is up, however bgp traffic from Azure does not seem to pass VPN blade correctly. The opposite direction works fine

VPN tunnel as per instructions, empty group in topology.
Now I am not too sure about VPN column in the policy. I might "borrowed" directional match configuration from aws, but I can't find any document to confirm what should I put in VPN column for Azure.
- Internal_clear > AWS VPN community
- AWS VPN community > AWS VPN community
- AWS VPN community > Internal_clear