Hello @Philip Kelley ,
Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
As @Andreas Baumgarten rightly said, if you use an Azure VPN Gateway with a Site-To-Site Connection the on-premises clients won't get new IP addresses.
A Site-to-Site (S2S) VPN gateway connection is a connection over IPsec/IKE (IKEv1 or IKEv2) VPN tunnel. A S2S connection requires a VPN device located on-premises that has a public IP address assigned to it. And the connection type could be either Route based or Policy based.
- RouteBased VPNs use "routes" in the IP forwarding or routing table to direct packets into their corresponding tunnel interfaces. The tunnel interfaces then encrypt or decrypt the packets in and out of the tunnels.
- Policy-based VPNs encrypt and direct packets through IPsec tunnels based on the IPsec policies configured with the combinations of address prefixes between your on-premises network and the Azure VNet.
Please refer : https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings#vpntype
You can find the steps on how to configure a Route-Based Site-to-Site IPsec VPN between a Microsoft Azure VPN gateway and an Ubiquiti EdgeRouter using static routing in the official doc below:
https://help.ui.com/hc/en-us/articles/115012305347
Kindly let us know if the above helps or you need further assistance on this issue.
----------------------------------------------------------------------------------------------------------------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.