Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
From your verbatim,
- You have a Hub VNET with VPN Gateway connected to OnPrem
- There is a Firewall deployed in the Hub VNET
- Traffic from neither the Hub VNET nor the Spokes VNET is able to connect to the OnPrem servers.
- However, there is a AKS service that was able to pass traffic to OnPrem.
As next steps,
- Can you confirm if the AKS is deployed in the HubVNET or one of the Spoke VNETs?
- I see you have a Firewall in HubVNET
- Did you configure UDRs in the subnets with OnPrem ----> FirewallPrivateIP
- If so, can you check the Firewall logs to see if the traffic to OnPrem actually hits the Firewall or Not?
- Create a new VM in the HubVNET in a new subnet (without any RouteTable)
- Let's call it testVM
- From this testVM, please try to access your OnPrem resources and let us know if that succeeds.
Cheers,
Kapil