An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
Hello,
Resources deployed in different subnets but under same VNET can communicate by default. You can setup NSG rules on top of specific subnet allowing inbound to only APPGW IP and deny other.
Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.