Hoping for some feeding on a possible cost-saving solution thought up within my team. Our web site is currently 3rd-party hosted. We want to move the web site to Azure, but see if we can route the web traffic through our on-prem mx250 and from there, route through our Azure IPsec tunnel to the web server (thus saving the cost of a firewall device in Azure if web traffic went there directly). We would utilize the DMZ/VLAN model to isolate this traffic from the rest of the network. I think our biggest concern is performance. Traffic is light to moderate to the site. Any thoughts are greatly appreciated.