Solved this in the end, https://imgur.com/a/GmP0gTa These routes fixed it above, applying to client VPN subnet ( 101.3 ) and gateway subnet to work with my MS Express route I never could ping he MX Natted IP in the end on it's private IP but seemed to work in the end This is probably really stupid but once I woke up and realised that the MX had to have it's own IP in the Client VPN range, I figured the Azure routing out, I was trying to route traffic via the main Natted IP of the MX I set in the config, but really I needed to do it via this hidden client vpn IP of the mx I didnt know existed
... View more