Change these to disable. Make sure the branches still show a route to the azure subnets but via the VMXs. Make sure Azure has a return route for the branch via one of the VMXs. Site to site VPN firewall rules are stateful for a single VMX and not across VMX - so be careful if you use these.
... View more