Hi @junior , I understand that you are using Virtual WAN, with VPN Gateway and Express Route Gateway in VHub, and you want to have routing for VPN2-4 via NVA (not in VHub).
Your scenario for VPN1 will work, as it's the default behaviour of VHub: route the advertised route directly, as VPN Gateway and VHub is BGP-peered.
Your scenario for VPN2-4 will not work. You can set a static route in VHub, for VPN2-4, go to NVA. But then, from NVA, it needs to go to Express Route Gateway, that is in VHub. Traffic goes back to VHub, and VHub has a static route: for VPN2-4, go to NVA. Routing loop.
It will work in Secure Hub scenario, as the Firewall is in VHub, so it knows the route directly to Express Route Gateway.