Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I am afraid I do not understand what your requirement here is.
From the newly created VNET, do you want the VMs' traffic to go to the NVA (Watchguard) ?
- Is my understanding correct?
- If so, NAT Gateway is not required
- You just have to use UDRs and point the traffic towards the NVA
- Attach a route table with 0.0.0.0/0 route with NextHopType as NVA and IP as the private IP of the NVA
- To all the subnets of the newly created VNET.
- You can refer to this where the NVA is the Azure Firewall
- You can follow the steps mentioned here and instead of Azure Firewall's Private IP, you can use your NVA's IP
Cheers,
Kapil