Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I see you have 2 test tenants.
Let's say vWAN is deployed in the Tenant1 and Tenant2 has VNET Gateway deployed to a VNET.
I am not sure what you mean by "VPN gateway separately with custom ASN and the create site on vwan and connect to hub"
- I am afraid this configuration is not feasible.
- You cannot use a VNET Gateway(deployed outside of vWAN) with a VPNSite(in a vWAN).
- If you deploy a VNET Gateway outside vWAN, you must use LNG with this.
- To use a VPNSite(in a vWAN), you must deploy a VPNGateway within the vWAN only.
- And this will be deployed as Active-Active and with a fixed ASN (65515) - users cannot change this behavior.
- Once you create a VPNGateway and Connect the VPNsite to a virtual hub(VPNGateway) , I see an option to see PSK
See:
Cheers,
Kapil.