Ok no UTM but routing and L4 firewall are necessity.
Anyway now I've all my on prem networks connected to the Azure site throught vMX auto vpn tunnel.
I can establish connetion from on prem clients to the Azure resources but I cannot establish connection from Azure resourses to my on prem devices.
Seems that vMX doesn't route the traffic from Azure to the on prem network.
Is this expected too?