Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
You would like to transit traffic coming from VPN Ipsec to Another site by ExpressRoute
The Flow IS ( On-Prem1) <IPSEC>(Azure)<ExpressRoute>(On-prem2).
For this configuration to work, you will be required to enable BGP in the,
- VPN Connection between OnPrem1 and Azure VPN Gateway
- Azure ExpressRoute to OnPrem2 (This should be already enabled)
For a Non - vWAN scenario
And, also, there are other requirements,
- If you want to use transit routing between ExpressRoute and VPN, the ASN of Azure VPN Gateway must be set to 65515 and Azure Route Server should be used.
- For ExpressRoute and Azure VPN to work together, you must keep the Autonomous System Number of your Azure VPN gateway at its default value, 65515
Refer : Azure Route Server support for ExpressRoute and Azure VPN
For a vWAN scenario
With Azure vWAN, you can do this directly.
No need for Azure Route server, but BGP would be required.
Consider the scenario : Any-to-Any,
Make sure you enable Branch-to-Branch in vWAN's configuration blade.
Refer: Is branch-to-branch connectivity allowed in Virtual WAN?
Kindly let us know if this helps or you need further assistance on this issue.
Thanks,
Kapil
Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.